@misc{oai:repo.qst.go.jp:00069973, author = {Tanikawa, Takumi and Kobashi, Gen and Ohta, Kaori and Mukai, Masami and Kobayashi, Akira and Ando, Yutaka and 谷川 琢海 and 小橋 元 and 太田 薫里 and 向井 まさみ and 小林 暁 and 安藤 裕}, month = {Nov}, note = {In order to clarify expected risks and to prepare tactics effectively, we constructed ISMS based on ISO/IEC 27001:2005 to a hospital. Security risks were extracted from an operation of a hospital information system and represented an ordering of priority. Tactics were prepared for reversible risks and the external audit was conducted for ISMS. Although ISMS was considered powerful tools for risk management, there were some problems to adjust medical field., AMIA 2009 Annual Symposium}, title = {Risk Management of Hospital Information Systems using Information Security Management Systems (ISMS)}, year = {2009} }