|
|
||||||||||||||||
|
|
|
|
|
|||||||||||||
|
|
Centers for Disease Control and Prevention Division of Cancer Prevention and Control 4770 Buford Hwy, NE MS K-64 Atlanta, GA 30341-3717 Call: 1 (800) CDC-INFO TTY: 1 (888) 232-6348 FAX: (770) 488-4760 E-mail: cdcinfo@cdc.gov |
|
|
|
Planning for Data SecurityExternal hackers and internal employees and former employees threaten the integrity of cancer registry data. To address these risks, organizations need to know—
Preventive security measures such as encryption, access control, and strong user identification technologies help protect sensitive data from external and internal threats. Developing a Security PolicyAll registries that submit data to the National Program of Cancer Registries (NPCR) should have a security policy that is specific to the needs of the registry and the organization in which the registry operates. This includes registries that are a part of a larger public health department, a university, or an institution that provides information technology support for several programs. The security policy of the organization in which the registry operates must meet or be modified to accommodate the specific concerns of the cancer registry. CDC's Division of Cancer Prevention and Control has compiled the following information in support of CDC's NPCR to help cancer registries create or audit their current security policy. This information is not intended establish cancer registry security policy, but to guide cancer registries as they address security issues. Many NPCR programs are part of a larger public health department, university, or institution that provides technical support for several programs and usually has a security policy in place. Each NPCR program and its organization's technical support staff are responsible for making cancer registry data secure. Both will devote time to security training and monitoring, and to reviewing and updating the security document. CDC's NPCR staff will work cooperatively to find solutions and develop best practices.
The Security DocumentEach registry should have a comprehensive security document that describes in detail the data security risks, policies, and procedures specific to that registry. Components of the security document include—
The registry's security document must accommodate the specific concerns of the NPCR program. It should ensure that security responsibilities are assigned to organization technical support and NPCR program staff, and authorize all information technology systems and software applications processing prior to installation. Internal AuditPeriodic internal auditing is key to maintaining the security document. Auditors review the major components of the security document and provide objective opinions to the registry on the degree to which risk management, control, and governance (which comprise the registry's policies, procedures, and operations) support—
These assessments help maintain or improve the efficiency and effectiveness of the registry's information technology risk management, internal controls, and security. In addition, auditors' recommendations benefit line management. As stated in NAACCR's Standards for Cancer Registries Volume III: Standards for Completeness, Quality, Analysis, Management, Security and Confidentiality of Data,* (PDF-969KB) the registry's parent organization may fulfill this function. Security LevelsFIPS 140-2 defines four levels of security:
Please visit FIPS 140-2 (PDF-1.4MB) for more information.
*Links to non-Federal organizations found at this site are provided solely as a service to our users. These links do not constitute an endorsement of these organizations or their programs by CDC or the Federal Government, and none should be inferred. CDC is not responsible for the content of the individual organization Web pages found at these links.
Page last reviewed: May 4, 2009
Page last updated: October 20, 2009 Content source: Division of Cancer Prevention and Control, National Center for Chronic Disease Prevention and Health Promotion |
|
|
|
|
||||||||||||
|