본문 바로가기 주메뉴 바로가기
국회도서관 홈으로 정보검색 소장정보 검색

결과 내 검색

동의어 포함

목차보기

Title page 1

Contents 4

Acknowledgments 6

Abbreviations and Acronyms 7

Executive Summary 8

Summary of key findings 9

Summary of recommendations 10

Introduction 13

Overview of the Health Sector in Andhra Pradesh 15

Overview of Cybersecurity Governance in Andhra Pradesh 19

The SCMM as Applied to the Health Sector 20

Using the SCMM to assess the health sector in Andhra Pradesh 21

Findings on Cybersecurity Maturity from the Assessment 26

Finding 1: Andhra Pradesh has a strong cybersecurity regulatory framework, but health sector cybersecurity practices are focused on a few... 30

Finding 2: No health authority formally oversees sector-level cybersecurity, hindering coordination 31

Finding 3: Public sector health facilities lack financial and human resources to address cybersecurity vulnerabilities 33

Finding 4: Health authorities lack a formal cybersecurity risk management strategy 33

Finding 5: Several baseline cybersecurity controls from the Andhra Pradesh Cyber Security Framework are partially implemented or absent... 34

Finding 6: Health sector staff have limited awareness of cyber threats and their impact on health service delivery 37

Finding 7: State policies stress cybersecurity capacity building, but the authorities do not collaborate with the health sector or train health... 37

Finding 8: Cybersecurity authorities lead incident response, but minimal follow-up with the health sector limits learning and improvement 38

Finding 9: Without organizational response planning, staff lack clear guidance for handling suspected incidents 40

Recommendations for Maturing Cybersecurity 42

Action path 1: Increase cybersecurity human capacity within the DoHFW and identify cybersecurity gaps and risks in the health sector 42

Action path 2: Increase cybersecurity knowledge and good practices in the health sector 48

Action path 3: Improve the governance and management of cybersecurity in the health sector 54

Action path 4: Strengthen cybersecurity measures and stakeholder collaboration 57

Summary of the action paths and recommendations 61

Conclusion 63

Glossary 64

References 70

Annex A. List of Basic Controls Mandated in the APCSF 75

Annex B. Recommendations Structured According to the SCMM Dimensions 92

Tables 20

Table 1. SCMM Layers of Assessment, Dimensions, and Factors 20

Table 2. Description of Stakeholders' Roles and Responsibilities Assessed in Line with the SCMM Layers of Assessment 24

Table 3. Cybersecurity Maturity Matrix of Andhra Pradesh's Health Sector 27

Table 4. Overview of the Key Findings 27

Table 5. Service Charges for the Cybersecurity Audit Assessments Provided by Andhra Pradesh Technology Services to Government Agencies 32

Table 6. Snapshot of Cybersecurity Measures in Place across the Sectoral Cybersecurity Maturity Model Indicators 35

Table 7. Proposed Approach to Training for the Leadership of the Department of Health and Family Welfare 49

Table 8. Proposed Approach to Training for the DoHFW IT team and IT/ABDM Staff in Public Health Facilities 50

Table 9. Proposed Approach to Training for Frontline Health Care Workers 52

Table 10. Strategic Planning Document Interactions 57

Table 11. Summary of Action Paths and Recommendations 61

Figures 16

Figure 1. Structure of the Three-Tier Health Care Facilities in Andhra Pradesh 16

Figure 2. Mobile and Web Applications and Platforms at the Primary Care Level in Andhra Pradesh 17

Figure 3. Mapping of Stakeholders Assessed along Cybersecurity Lines of Responsibilities 22

Figure 4. Incident Response Life Cycle Model Based on the National Institute of Standards and Technology Cybersecurity Framework 2.0... 39

Figure 5. National Institute of Standards and Technology Incident Response Life Cycle 56

Boxes 23

Box 1. Levels of Assessment (LoAs) 23

Box 2. Overview of Activities That APTS Can Support 30

Box 3. Roles and Responsibilities of the Single Point of Contact 31

Box 4. Summary of the Incident Response Protocol Followed by the APCSOC 38

Box 5. Suggested Responsibilities of the Cybersecurity Specialists 43

Box 6. International Best Practice Example: Cybersecurity Information Platforms for the Health Sector in England 59

Annex Tables 75

Table A1. List of Basic Controls Mandated in the Andhra Pradesh Cyber Security Framework 75

Table B1. Nonsequential Summary of Recommendations Structured According to the Sectoral Cybersecurity Maturity Model Dimensions 92