Policy addressing Information Security for the Swiss Personalized Health Network


 

3 September 2018

Today we publish the Information Security Policy, a joint effort by subject matter experts across the SPHN coordinated by Heinz Stockinger, Chief Technology Officer at the SIB Swiss Institute of Bioinformatics. Heinz also chairs the SPHN DCC Working Group that advises on IT infrastructure (storage and HPC) and practical IT security measures for the BioMedIT nodes in SPHN.

This information security policy clarifies the roles and responsibilities of various parties relative to Information Security. Additionally, it defines the technical and organisational measures necessary to operate IT infrastructures that support SPHN projects. The policy is complementary to the SPHN Ethical Framework for Responsible Data Processing.

 

Who should read and follow the policy?

This policy applies to research IT infrastructure providers at Swiss academic institutions (e.g. BioMedIT Nodes), project leaders and data users within SPHN projects and related projects where applicable.
This policy does not apply to IT infrastructures within hospitals since they comply with their own respective policies.

 

In summary, every SPHN project that uses confidential personal data on one of the BioMedIT Nodes needs to adhere to this policy. A dedicated training is provided to make sure that project leaders, users and system administrators are fully aware of their obligations with respect to the policy as well as related Swiss laws and regulations.
For specific information on information security policies – contact Heinz Stockinger, heinz.stockinger@sib.swiss

 

Icon SPHN Information Security Policy (163.7 KB)

Icon SPHN Ethical Framework for Responsible Data Processing (221.6 KB)