This wiki has undergone a migration to Confluence found Here
Difference between revisions of "HL7 FHIR security topics"
Jump to navigation
Jump to search
JohnMoehrke (talk | contribs) |
|||
Line 2: | Line 2: | ||
* '''[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemBrowse&tracker_id=677&tracker_query_id=4968 FHIR disposition link on gForge]''' for review/discussion (ongoing weekly agenda item) | * '''[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemBrowse&tracker_id=677&tracker_query_id=4968 FHIR disposition link on gForge]''' for review/discussion (ongoing weekly agenda item) | ||
+ | |||
+ | ==Export from Gforge Security Open== | ||
+ | Wiki | ||
+ | |||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=3318 3318] Clarify how to use RBAC and ABAC using FHIR () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=5525 5525] Consent Directive does not appear to be aligned with the 80% () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=6303 6303] Add Record Lifecycle Events to AuditEventObjectLifecycle Set () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7563 7563] 2015May core #854 - Expand on how to use Provenance () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7567 7567] 2015May core #858 - Provenance isn't sufficiently aligned with w3c spec () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7568 7568] 2015May core #859 - How are agent and activity linked? () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7569 7569] 2015May core #860 - Clarify relationship agents and entities used in activity () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7570 7570] 2015May core #861 - Clarify relationship agents and entities used in activity () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7597 7597] 2015May core #888 - This resource is missing any reference to the "action" performed on the entity. Is there a default "create" action or is it an omission? () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=7598 7598] 2015May core #889 - Can Provenance apply to a resource or just a data element () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8638 8638] how does Provenance work when deleting records () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8731 8731] Canonicalization for signatures () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8738 8738] Unapplied QA changes around security and services () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8790 8790] Give guidance on AuditEvent that codes don't need DisplayName populated () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8803 8803] Provenance for a subset of a resource () | ||
+ | *[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=8827 8827] Signature datatype does not include counter-signature type () | ||
+ | |||
+ | ==Other== | ||
* [http://hl7-fhir.github.io/security.html Security] pages | * [http://hl7-fhir.github.io/security.html Security] pages | ||
** Including guidance on Authentication and Authorization | ** Including guidance on Authentication and Authorization |
Revision as of 22:09, 3 November 2015
Project ID 1209
- FHIR disposition link on gForge for review/discussion (ongoing weekly agenda item)
Export from Gforge Security Open
Wiki
- 3318 Clarify how to use RBAC and ABAC using FHIR ()
- 5525 Consent Directive does not appear to be aligned with the 80% ()
- 6303 Add Record Lifecycle Events to AuditEventObjectLifecycle Set ()
- 7563 2015May core #854 - Expand on how to use Provenance ()
- 7567 2015May core #858 - Provenance isn't sufficiently aligned with w3c spec ()
- 7568 2015May core #859 - How are agent and activity linked? ()
- 7569 2015May core #860 - Clarify relationship agents and entities used in activity ()
- 7570 2015May core #861 - Clarify relationship agents and entities used in activity ()
- 7597 2015May core #888 - This resource is missing any reference to the "action" performed on the entity. Is there a default "create" action or is it an omission? ()
- 7598 2015May core #889 - Can Provenance apply to a resource or just a data element ()
- 8638 how does Provenance work when deleting records ()
- 8731 Canonicalization for signatures ()
- 8738 Unapplied QA changes around security and services ()
- 8790 Give guidance on AuditEvent that codes don't need DisplayName populated ()
- 8803 Provenance for a subset of a resource ()
- 8827 Signature datatype does not include counter-signature type ()
Other
- Security pages
- Including guidance on Authentication and Authorization
- Security Labels Page
- including meta tag use for security labels
- Signature Data Type
Provenance Resource
- Address outstanding Provenance CPs from January 2015 FHIR Ballot mistakenly assigned to FHIR Infrastructure
- Including signature use within Provenance
- Provenance.activity value-set needs to be enlarged with existing vocabulary, and discussion around if it should be marked as Extensible.
- Provenance.entity.role unclear how each vocabulary item should be used.
- how is derivation to be used?
- how is revision to be used, other than the duplicate indication that would be in Provenance.activity.
- Provenance.reason binding only to the PurposeOfUse is not granular. Seems there should be a more clear distinction between reason and activity. question on why this is Extensible
- show how a resource and provenance would look as that resource transitions through lifecycle. In this way one would be able to find each step of the lifecycle, by way of version; and the provenance statement by way of the pointer to that version specific.
- Detailed work plan and notes HL7 FHIR Provenance Resource
AuditEvent Resource
- Address outstanding AuditEvent CPs from January 2015 FHIR Ballot mistakenly assigned to FHIR Infrastructure
- harmonize the structure, element names, and vocabulary as much as possible with Provenance.
- document use cases for interoperable FHIR AuditEvent - e.g., federated system with central AuditEvent Service - intra- and inter-enterprise.
- address the thought experiment of why do we have both Provenance and AuditEvent. (motivation vs consequence) (medical records vs security surveillance)
- See http://hl7-fhir.github.io/auditevent-mappings.html#w3c.prov
- See http://hl7-fhir.github.io/auditevent-mappings.html#fhirprovenance
- See http://hl7-fhir.github.io/provenance-mappings.html#w3c.prov
- See http://hl7-fhir.github.io/provenance-mappings.html#fhirauditevent
- See http://hl7-fhir.github.io/w5
- Who records Provenance vs AuditEvent; what are the various architectures. The important point is to assure that the architecture chosen doesn't miss information.
- and various other things concerning Security -- Risks to Confidentiality, Integrity, and Availability.
- also interested in
- W5
- Privacy Consent as a profile on Contract