基于态势感知平台的大型医院网络安全风险管理实践
作者:
作者单位:

(郑州大学第一附属医院信息处 郑州 450002)

作者简介:

孙保峰,工程师,发表论文9篇;通信作者:杨扬,高级工程师,硕士生导师。〔基金项目〕

通讯作者:

中图分类号:

基金项目:

河南省医学科技攻关计划软科学重点项目(项目编号:RKX202201007)。


Practice of Cybersecurity Risk Management in Large Hospitals Based on a Situational Awareness Platform
Author:
Affiliation:

(Information Department, the First Affiliated Hospital of Zhengzhou University, Zhengzhou 450002,China)

Fund Project:

  • 摘要
  • 图/表
  • 访问统计
  • 参考文献
  • 相似文献
  • 引证文献
  • 资源附件
  • 文章评论
    摘要:

    分析大型医院态势感知平台所监测到的网络安全风险事件,探明其产生的原因,提出解决方法和改善建议。方法/过程 以郑州大学第一附属医院为例,对态势感知平台风险事件聚合分析,筛选医院内网风险终端,并进行整改加固,分析风险终端的科室分布和成因,提出改善建议。结果/结论 医技科室风险终端数量较多,主要原因在于缺乏管理及未做到防病毒软件全覆盖。通过风险终端整改加固,网络安全风险事件数量明显减少。加强医院终端安全管理、提升人员网络安全意识、分区加强网络安全防护可有效降低医院网络安全风险事件发生率,提升医院网络安全防护能力。

    Abstract:

    To analyze the network security risk events monitored by the situational awareness platform of large hospitals, to find out the causes, and to put forward solutions and suggestions for improvement. Method/Process Taking the First Affiliated Hospital of Zhengzhou University as an example, the paper analyzes risk events on the situational awareness platform, screens the risky terminals on the hospital intranet, carries out rectification and reinforcement, analyzes the department distribution and causes of risky terminals, and puts forward suggestions for improvement. Result/Conclusion The number of risky terminals in medical and technical departments is large, mainly due to the lack of management and the lack of full coverage of antivirus software. Through the rectification and reinforcement of risky terminals, the number of network security risk events has been significantly reduced. Strengthening the hospital terminal security management, enhancing staff awareness of network security, and strengthening network security protection in different areas can effectively reduce the incidence of hospital network security risk events and improve the hospital network security protection capability.

    参考文献
    相似文献
    引证文献
引用本文

孙保峰,张伟祎,杨扬,等.基于态势感知平台的大型医院网络安全风险管理实践[J].医学信息学杂志,2024,45(10):81-85

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:2024-08-27
  • 录用日期:
  • 在线发布日期: 2024-11-14
  • 出版日期:

扫码关注

官方微信