A risk assessment (RA) framework was employed to determine what protection would be adequate and reasonable for the assets of a cardiology eHealth service deployed on the island of Crete. In the context of HYGEIAnet, the regional health telematics network of Crete, teleconsultation services for cardiology patients have been installed and are in routine use since December 2000. The novelty of the framework for model-based RA of security critical systems, which developed within the CORAS IST project, lays in its synthesis of risk analysis methods with semiformal specification, supported by an adaptable tool-integration platform. This paper presents the use of the CORAS framework to assess the cardiology eHealth service and the implementation of security controls and mechanisms.
No takes yet. Share an insight, caveat, or question.
Stathiakis et al. (2003) studied this question.