Informationsteknik, kontorsutrustning
- +Ämnesområden
- +Informationsteknik, kontorsutrustning (28)
- Informationsteknik: allmänt (2)
- IT-säkerhet (4)
- +Kodning av information (2)
- Programspråk (0)
- Programutveckling och systemdokumentation (1)
- +Öppna system (OSI) (0)
- Nätarkitekturer (0)
- Datorgrafik (0)
- Mikroprocessorsystem (0)
- Terminalutrustning och övrig kringutrustning (0)
- Gränssnitt och anslutningsutrustning (0)
- Molnbaserade datortjänster (0)
- +Datalagringsmedier (0)
- +IT-tillämpningar (23)
- Kontorsutrustning (0)
This document provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011. This document is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme.
This document establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect personally identifiable information (PII) in line with the privacy principles in ISO/IEC 29100 for the public cloud computing environment. In particular, this document specifies guidelines based on ISO/IEC 27002:2022, taking into consideration the regulatory requirements for the protection of PII which can be applicable within the context of the information security risk environment(s) of a provider of public cloud services. This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which provide information processing services as PII processors via cloud computing under contract to other organizations. The guidelines in this document can also be relevant to organizations acting as PII controllers.
This document provides a privacy framework which: — specifies a common privacy terminology; — defines the actors and their roles in processing personally identifiable information (PII); — describes privacy safeguarding considerations; — provides references to known privacy principles for information technology. This document is applicable to natural persons and organizations involved in specifying, procuring, architecting, designing, developing, testing, maintaining, administering, and operating information and communication technology systems or services where privacy controls are required for the processing of PII
This document defines cyber security requirements for products with digital elements belonging to product category “Hardware Device with Security Boxes” (hereinafter called “Product” or “HWSB product”). The technical description of “Hardware Devices with Security Boxes” can be found in Annex II of [CRA]. The Hardware Devices with Security Boxes in scope are designed for deployment in a range of environments and where the threat landscape includes attackers with various attack potential. HWSB are hardware-based systems intended to provide secure storage, processing and use of sensitive data, including cryptographic assets, within a protected hardware boundary (envelope). This document applies to the HWSB part of the product. The applicability of this document to specific products is determined based on their intended purpose, use case and risk assessment.
This project aims at covering the line 16 of the standardisation request and will provide: • General description of the Product with digital elements belonging to that category and the product and/or components such Product with digital elements may integrate, including – amongst other: o detailed description of that product category using in: Identity management systems hardware and software are products with digital elements that provide mechanisms for identity lifecycle management, such as identity provisioning, maintenance, authentication, authorisation and deprovisioning, and including associated metadata. Privileged access management hardware and software are products with digital elements that authenticate and authorise users or devices, granting or denying access to digital resources or to physical locations. This category includes but is not limited to products (hardware, software and communication protocol) with digital elements that have the core functionality of either or both identity management and privileged access management; authentication and access control readers; biometric readers; single sign-on software; federated identity management software, protection and safety management (such as access control, intrusion alarm, CCTV and fire safety systems) and multi-factor authentication software. o Intended product purpose and reasonably foreseeable use in the above categories; o Identification of the various types of Products with digital elements; o Delineation and interplay with the following other categories of Product with digital elements (identified by their line in the standardization request): line 17 line 18 line 20 line 24 line 28 line 29 line 32 line 35 line 37 line 38 line 39 line 41 • Description of their life cycle; • Relevance of cybersecurity essential requirements including the cybersecurity assessment requirements; • Definition of applicable risk profiles to be considered for these Product with digital elements; • Applicable cybersecurity requirements ensuring fulfillment of the essential requirements for each risk profile; • Applicable cybersecurity assessment requirements for each risk profile. A base document is provided • Defining the risk profiles; • Identifying initial cybersecurity security requirements.
This document specifies a means for communicating part or all of the electronic health record (EHR) of one or more identified subjects of care between EHR systems, or between EHR systems and a centralised EHR data repository. It can also be used for EHR communication between an EHR system or repository and clinical applications or middleware components (such as decision support components), or personal health applications and devices, that need to access or provide EHR data, or as the representation of EHR data within a distributed (federated) record system. This document will predominantly be used to support the direct care given to identifiable individuals or self-care by individuals themselves, or to support population monitoring systems such as disease registries and public health surveillance. Uses of health records for other purposes such as teaching, clinical audit, administration and reporting, service management, research and epidemiology, which often require anonymization or aggregation of individual records, are not the focus of this document but such secondary uses might also find the document useful. This Part 1 of the multipart series is an Information Viewpoint specification as defined by the Open Distributed Processing ? Reference model: Overview (ISO/IEC 10746-1). This document is not intended to specify the internal architecture or database design of EHR systems.
This document specifies requirements for the preparation, revision and presentation of digital product definition data, hereafter referred to as data sets, complementing existing standards. It supports two methods of application: 3D model-only and 3D model with 2D drawing in digital format. The structure of this document presents requirements common to both methods followed by clauses providing for any essential, differing requirements for each method. Additionally, its use in conjunction with computer-aided design (CAD) systems can assist in the progression towards improved modelling and annotation practices for CAD and engineering disciplines, as well as serving as a guideline for CAx software developers.
The actual definitions for the interpretation, in particular the ISO TPD and ISO GPS rules, are taken from the original definition standards, e.g. ISO 129-1 and ISO 1101.
When the term model is used in this document it applies to both design models and annotated models.
This document outlines a core dataset designed for a concise dental data exchange intended to support continuity and coordination of care. It provides a conceptual framework for a dental data for exchange that can serve as the basis for implementation models. The content reflects an international perspective on organizing dental information for cross-border exchange. It offers guidance on the essential data elements that should be shared globally and proposes a standardized format for their representation. The document focuses on defining the structure of the data to be exchanged (“the what”) without prescribing the specific methods or technologies used for transmission (“the how”). It does not include guidance on operational workflows such as data entry, collection, summarization, or integration. Nor does it address the competencies required to perform those tasks. Furthermore, it is not intended as an implementation guide and does not cover the underlying technical infrastructure or the use of particular coding systems, data formats, or terminologies.
Within the context of the ISO/IEEE 11073 family of standards for device communication, a normative definition of the communication between personal basic electrocardiograph (ECG) devices and managers (e.g. cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability is established in ISO/IEEE11073-10406:2012. Appropriate portions of existing standards including ISO/IEEE 11073 terminology and IEEE 11073-20601 information models are leveraged. The use of specific term codes, formats and behaviours in telehealth environments restricting optionality in base frameworks in favour of interoperability is specified. A common core of communication functionality for personal telehealth basic ECG (1- to 3-lead ECG) devices is defined. Monitoring ECG devices are distinguished from diagnostic ECG equipment with respect to support for wearable ECG devices, limiting the number of leads supported by the equipment to three, and not requiring the capability of annotating or analysing the detected electrical activity to determine known cardiac phenomena. ISO/IEEE 11073-10406:2012 is consistent with the base framework and allows multifunction implementations by following multiple device specializations (e.g. ECG and respiration rate).
Within the context of the ISO/IEEE 11073 family of standards for device communication, ISO/IEEE 11073-10417:2017 establishes a normative definition of communication between personal telehealth glucose meter devices and compute engines (e.g., cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability. It leverages appropriate portions of existing standards, including ISO/IEEE 11073 terminology, information models, application profile standards, and transport standards. It specifies the use of specific term codes, formats, and behaviors in telehealth environments restricting optionality in base frameworks in favor of interoperability. This standard defines a common core of communication functionality for personal telehealth glucose meters.
This standard will provide a description of the numbering system replacing the DOMES numbering. The description of the DOMES numbering can be found in MERIT/COTES joint working groups, MERIT campaign: connection of reference frames, implementation plan, 1983. The standard will provide to the geodetic data producers and users a proper identification of the permanently instrumented stations, (e.g. those used in the production of the International Terrestrial Reference Frame and other similar stations), with special emphasis on the backward compatibility with existing DOMES numbers, which will have a positive impact on interoperability issues when merging several data from different communities. This standard will: • support interoperability among GNSS providers (GPS, GLONASS, GALILEO, BEIDOU, …) • clarify the potential confusion between communities which have already adopted their own numbering systems • support the UNGGIM GGRF resolution on global geodetic infrastructure.
Abstract: Within the context of the ISO/IEEE 11073 family of standards for device communication, this standard establishes a normative definition of the communication between personal strength fitness devices and managers (e.g., cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability. It leverages appropriate portions of existing standards including ISO/IEEE 11073 terminology and information models. It specifies the use of specific term codes, formats, and behaviors in telehealth environments restricting optionality in base frameworks in favor of interoperability. This standard defines a common core of communication functionality for personal telehealth strength fitness devices. In this context, strength fitness devices are being used broadly to cover strength fitness devices that measure musculo-skeletal strength-conditioning activities. Keywords: medical device communication, personal health devices, strength fitness equipment
This standard establishes a normative definition of communication between personal telehealth insulin pump devices (agents) and managers (e.g., cell phones, personal computers, personal health appliances, set top boxes) in a manner that enables plug-and-play interoperability. It leverages work done in other ISO/IEEE 11073 standards including existing terminology, information profiles, application profile standards, and transport standards. It specifies the use of specific term codes, formats, and behaviors in telehealth environments, restricting optionality in base frameworks in favor of interoperability. This standard defines a common core functionality of personal telehealth insulin pump devices. In the context of personal health devices (PHDs), an insulin pump is a medical device used for the administration of insulin in the treatment of diabetes mellitus, also known as continuous subcutaneous insulin infusion (CSII) therapy. This standard provides the data modeling according to ISO/IEEE 11073-20601 and does not specify the measurement method.
Within the context of the ISO/IEEE 11073 family of standards for device communication, a normative definition of the communication between personal basic electrocardiograph (ECG) devices and managers (e.g. cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability is established in ISO/IEEE11073-10406:2012. Appropriate portions of existing standards including ISO/IEEE 11073 terminology and IEEE 11073-20601 information models are leveraged. The use of specific term codes, formats and behaviours in telehealth environments restricting optionality in base frameworks in favour of interoperability is specified. A common core of communication functionality for personal telehealth basic ECG (1- to 3-lead ECG) devices is defined. Monitoring ECG devices are distinguished from diagnostic ECG equipment with respect to support for wearable ECG devices, limiting the number of leads supported by the equipment to three, and not requiring the capability of annotating or analysing the detected electrical activity to determine known cardiac phenomena. ISO/IEEE 11073-10406:2012 is consistent with the base framework and allows multifunction implementations by following multiple device specializations (e.g. ECG and respiration rate).
Within the context of the ISO/IEEE 11073 family of standards for device communication, ISO/IEEE 11073-10417:2017 establishes a normative definition of communication between personal telehealth glucose meter devices and compute engines (e.g., cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability. It leverages appropriate portions of existing standards, including ISO/IEEE 11073 terminology, information models, application profile standards, and transport standards. It specifies the use of specific term codes, formats, and behaviors in telehealth environments restricting optionality in base frameworks in favor of interoperability. This standard defines a common core of communication functionality for personal telehealth glucose meters.
Abstract: Within the context of the ISO/IEEE 11073 family of standards for device communication, this standard establishes a normative definition of the communication between personal strength fitness devices and managers (e.g., cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability. It leverages appropriate portions of existing standards including ISO/IEEE 11073 terminology and information models. It specifies the use of specific term codes, formats, and behaviors in telehealth environments restricting optionality in base frameworks in favor of interoperability. This standard defines a common core of communication functionality for personal telehealth strength fitness devices. In this context, strength fitness devices are being used broadly to cover strength fitness devices that measure musculo-skeletal strength-conditioning activities. Keywords: medical device communication, personal health devices, strength fitness equipment
Within the context of the ISO/IEEE 11073 family of standards for device communication, a normative definition of the communication between personal basic electrocardiograph (ECG) devices and managers (e.g. cell phones, personal computers, personal health appliances, and set top boxes) in a manner that enables plug-and-play interoperability is established in ISO/IEEE11073-10406:2012. Appropriate portions of existing standards including ISO/IEEE 11073 terminology and IEEE 11073-20601 information models are leveraged. The use of specific term codes, formats and behaviours in telehealth environments restricting optionality in base frameworks in favour of interoperability is specified. A common core of communication functionality for personal telehealth basic ECG (1- to 3-lead ECG) devices is defined. Monitoring ECG devices are distinguished from diagnostic ECG equipment with respect to support for wearable ECG devices, limiting the number of leads supported by the equipment to three, and not requiring the capability of annotating or analysing the detected electrical activity to determine known cardiac phenomena. ISO/IEEE 11073-10406:2012 is consistent with the base framework and allows multifunction implementations by following multiple device specializations (e.g. ECG and respiration rate).
This document specifies the in-vehicle information (IVI) data structures that are required by different intelligent transport system (ITS) services for exchanging information between ITS stations (ITS-S). A general, extensible data structure is specified, which is split into structures called containers to accommodate current-day information. Transmitted information includes IVI such as contextual speed, road works warnings, vehicle restrictions, lane restrictions, road hazard warnings, location-based services and re-routing. The information in the containers is organized in sub-structures called data frames and data elements, which are described in terms of their content and syntax. The data structures are specified as communications-agnostic. This document does not provide the communication protocols. This document provides scenarios for usage of the data structure, e.g. in case of real time, short-range communications.
This document specifies:
— the interfaces between electronic fee collection (EFC) back-office systems for vehicle-related transport services, e.g. road user charging, parking and access control;
— an exchange of information between the back-office system of the two roles of service provision and toll charging, e.g.:
— charging-related data (toll declarations, billing details, payment claims, payment announcements),
— administrative data (trust objects, EFC context data, etc.), and
— confirmation data;
— transfer mechanisms and supporting functions;
— information objects, data syntax and semantics.
This document is applicable for any vehicle-related toll service and any technology used for charging.
The data types and associated coding related to the data elements described in Clause 6 are specified in Annex A, using the abstract syntax notation one (ASN.1) according to ISO/IEC 8824-1.
This document specifies basic protocol mechanisms over which implementations can specify and perform complex transfers (transactions).
This document does not specify, amongst others:
— any communication between TC or TSP with any other involved party;
— any communication between elements of the TC and the TSP that is not part of the back-office communication;
— interfaces for EFC systems for public transport;
— any complex transfers (transactions), i.e. sequences of inter-related ADUs that can possibly involve several APDU exchanges;
— processes regarding payments and exchanges of fiscal, commercial or legal accounting documents;
— definitions of service communication channels, protocols and service primitives to transfer the APDU.
Amendment
1 Scope
Replace the last paragraph with the following text (in which “any complex transfers (transactions), i.e.
sequences of inter-related ADUs that can possibly involve several APDU exchanges has been removed”):
This document does not specify, amongst others:
— any communication between TC or TSP with any other involved party;
— any communication between elements of the TC and the TSP that is not part of the back-office
communication;
— interfaces for EFC systems for public transport;
— processes regarding payments and exchanges of fiscal, commercial or legal accounting documents;
— definitions of service communication channels, protocols and service primitives to transfer the APDU.
This document specifies methodologies for measuring the performance of AI models for classification, regression, clustering and recommendation tasks.