IV. Managing the Risks of Moving to Electronic Records
Ensure the appropriate level and type of security.
To mitigate the risks discussed in Section II, " Identifying the Risks
and Benefits of Moving From Paper to Electronic Transactions and Records,"
section of this document, the appropriate levels and types of security functionality
must be built into the system. This functionality must be consistent with the risk
assessment and cost/benefit analysis discussed in that section. A detailed
discussion of security levels, methods and technologies is beyond the scope of this
document. Following is a very high-level description:
- Levels of security based on risk assessment:
- Types of security that may be required:
-
Authentication establishes the
validity of a transmission, message, and its originator.
-
Confidentiality restricts access
of a record to only those authorized to view it.
-
Data integrity addresses the
unauthorized or accidental modification of a record.
-
Non-repudiation prevents an
individual from denying that previous actions had been performed or
intent expressed in a record.
- Types of security tools:
- PINs and passwords
- Digital signatures
- Encryption
- Biometric devices
