| Literature DB >> 28330491 |
Marco Brandizi1, Olga Melnichuk2, Raffael Bild3, Florian Kohlmayer3, Benedicto Rodriguez-Castro3, Helmut Spengler3, Klaus A Kuhn3, Wolfgang Kuchinke4, Christian Ohmann5, Timo Mustonen6, Mikael Linden6, Tommi Nyrönen6, Ilkka Lappalainen6, Alvis Brazma2, Ugis Sarkans7.
Abstract
BACKGROUND: Translational researchers need robust IT solutions to access a range of data types, varying from public data sets to pseudonymised patient information with restricted access, provided on a case by case basis. The reason for this complication is that managing access policies to sensitive human data must consider issues of data confidentiality, identifiability, extent of consent, and data usage agreements. All these ethical, social and legal aspects must be incorporated into a differential management of restricted access to sensitive data.Entities:
Keywords: Biomedical Data; Clinical Data; Data Access; Health Data Protection; Translational Research
Mesh:
Year: 2017 PMID: 28330491 PMCID: PMC5363029 DOI: 10.1186/s12911-017-0424-6
Source DB: PubMed Journal: BMC Med Inform Decis Mak ISSN: 1472-6947 Impact factor: 2.796
Fig. 1The workflow implemented for the BioMedBridges secure access pilot. Taken from [39]
How STRIDE threats are addressed in the pilot (or could be in similar scenario)
| STRIDE Threat/ Function | Shibboleth/Id Federation | REMS | Domain Apps (BioSD, BBMRI Hub, more) | Infrastructure (eg, web servers, network) |
|---|---|---|---|---|
| Spoofing/Authenticity | Authentication HTTPS/TLS/X.509 | Limit distributed attributes | PSE | - HTTPS/TLS/ X.509 - PSE |
| Repudiation/Accountability | Authentication Logging (must be law-compliant, eg max retention time) | Logging | - Logging | - Logging |
| Info Disclosure/Confidentiality | HTTPS/TLS/X.509 | - Subscribed policies (no data out of Id Federation) | HTTPS/TLS/X.509 | HTTPS/TLS/X.509 |
| DoS/ Availability | - PSE | - PSE | - PSE | - Redundancy |
| Elevation of Privileges/Authorisation | - Only required attributes distributed | - Only required attributes distributed | - PSE | - PSE |
PSE refers to software design and testing, best practices, established methodologies, techniques and frameworks. As for the biomedical-specific risks identified by the LINDUN methodology, REMS policies help with facing all those risks, as it does the security and reliability of the pilot software components