Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

(4 pts) Consider a computer in a hospital that controls the radiation dosage, ex

ID: 3876545 • Letter: #

Question

(4 pts) Consider a computer in a hospital that controls the radiation dosage, exposure time, and bed movement for a CT scan machine. It receives input from the hospital’s network in the form of a record containing a patient number and settings for the scan. Then it sends signals to the hardware to perform the scan according to those settings.

List Confidentiality, Integrity, and Availability requirements for the data and services that such a machine is responsible for.

For each of the requirements, indicate the degree of seriousness (high/medium/low) if the requirement is broken. Justify your answer.

(4 pts) Repeat problem 1, but this time with the scenario of an email server that stores and transmits email messages for a national government agency involved in classified communications.

Explanation / Answer

Now in order to understand the concern of confidentiality, integrity, and availability  in healthcare sector due to different devices firstly let as take an example

In year 2004,there was a case registered of over exposure of radiation in France. Which was lead by an IT field error (data integrity) meant that excessive doses of irradiation were provided to patients, which leads to number of deaths.

Let us take onother example when the there is a hospital chain(Medstar) which was the victim of a cyber-attack known as Cryptolocker which leads to the shutdown of IT system of the hospital .Due to this the hospital had to send patients to other hospitals it was a issue of availability.

Now if we considered your scenario and talk about integrity issue related to devices used in your problem then overdose of radiation dosage is highly dangerous and may lead to death of patient where as exposure and and bed movement also considered seriously as they have the major responsibility of right treatment The only tools that have ability to reduce these kinds of risks are software qualification tests which needs to carried out time to time by the software vendors .

Now if we talk about the availability issues in these devices to deals with a hardware failure, you must have backup equipment

And if we talk about confidentiality it was not a major issues but if we have to protect identity of patient (ie- we doesnot want to disclose the reason of CT scan ) then   a different name is entered in the system so if the system is hacked into, the person’s real identity will be protected.

In such cases Where acute care is the major concerned , the major factor is data integrity, which is followed by availability, and then, confidentiality.

For other questions to be answered please provide as separate question

Thankyou