ISO 17090-3 is the third part of an international multi-series standard that deals with health informatics. ISO 17090-3 gives guidelines for certificate management issues involved in deploying digital certificates in healthcare. It specifies a structure and minimum requirements for certificate policies, as well as a structure for associated certification practice statements.
ISO 17090-3 also identifies the principles needed in a healthcare security policy for cross-border communication and defines the minimum levels of security required, concentrating on aspects unique to healthcare.
BS ISO 17090-3 on policy management of certification authority is useful for:
The proper deployment of digital certificates requires a blend of technology, policy, and administrative processes that enable the exchange of sensitive data in an unsecured environment. It uses “public-key cryptography” to protect the information in transit and “certificates” to confirm the identity of a person or entity.
ISO 17090-3 describes the common technical, operational, and policy requirements that need to be addressed which helps you enable digital certificates to be used, in protecting the exchange of healthcare information within a single domain, between domains, and across jurisdictional boundaries.
ISO 17090-3 serves the purpose to create a platform for global interoperability. It specifically supports digital certificate-enabled communication across borders but could also provide you with guidance for the national or regional deployment of digital certificates in healthcare.
As the Internet is increasingly used as the vehicle of choice, ISO 17090-3 helps its users to support the movement of healthcare data between healthcare organizations and is the realistic choice for cross-border communication in this sector.
BS ISO 17090-3:2021 supersedes BS ISO 170903:2008, which is withdrawn. BS ISO 17090-3:2021 includes some technical changes with respect to BS ISO 170903:2008. These include:
ISO 17090-3:2021