<?xml version="1.0" encoding="UTF-8"?><toc><section id="foreword.nat"><title>Nationales Vorwort</title></section><section id="foreword.reg"><title>Vorwort</title></section><section id="sub-endorsement.notice"><title>Anerkennungsnotiz</title></section><section id="introduction.int"><title>Einleitung</title></section><section id="sub-1"><label>1</label><title>Anwendungsbereich</title></section><section id="sub-2"><label>2</label><title>Normative Verweisungen</title></section><section id="sub-3"><label>3</label><title>Begriffe</title><section id="sub-3.1"><label>3.1</label><title>Zugriffssteuerung</title></section><section id="sub-3.2"><label>3.2</label><title>Zurechenbarkeit</title></section><section id="sub-3.3"><label>3.3</label><title>Attributzertifikat</title></section><section id="sub-3.4"><label>3.4</label><title>Authentisierung</title></section><section id="sub-3.5"><label>3.5</label><title>Autorisierer</title></section><section id="sub-3.6"><label>3.6</label><title>Autorisierung</title></section><section id="sub-3.7"><label>3.7</label><title>Verfügbarkeit</title></section><section id="sub-3.8"><label>3.8</label><title>Zertifizierungsstelle</title></section><section id="sub-3.9"><label>3.9</label><title>Vertraulichkeit</title></section><section id="sub-3.10"><label>3.10</label><title>Delegierung</title></section><section id="sub-3.11"><label>3.11</label><title>Identifizierung</title></section><section id="sub-3.12"><label>3.12</label><title>Schlüssel</title></section><section id="sub-3.13"><label>3.13</label><title>Policy</title></section><section id="sub-3.14"><label>3.14</label><title>Policy-Vereinbarung</title></section><section id="sub-3.15"><label>3.15</label><title>Principal</title></section><section id="sub-3.16"><label>3.16</label><title>privater Schlüssel</title></section><section id="sub-3.17"><label>3.17</label><title>Privileg</title></section><section id="sub-3.18"><label>3.18</label><title>öffentlicher Schlüssel</title></section><section id="sub-3.19"><label>3.19</label><title>Rolle</title></section><section id="sub-3.20"><label>3.20</label><title>Sicherheit</title></section><section id="sub-3.21"><label>3.21</label><title>Sicherheits-Policy</title></section><section id="sub-3.22"><label>3.22</label><title>Sicherheitsdienst</title></section><section id="sub-3.23"><label>3.23</label><title>starke Authentisierung</title></section><section id="sub-3.24"><label>3.24</label><title>Ziel</title></section></section><section id="sub-4"><label>4</label><title>Abkürzungen</title></section><section id="sub-5"><label>5</label><title>Ziel und Struktur von Privilegienmanagement und Zugriffssteuerung</title><section id="sub-5.1"><label>5.1</label><title>Ziel von Privilegienmanagement und Zugriffssteuerung</title></section><section id="sub-5.2"><label>5.2</label><title>Struktur von Privilegienmanagement und Zugriffssteuerung</title><section id="sub-5.2.1"><label>5.2.1</label><title>Strukturelemente</title></section><section id="sub-5.2.2"><label>5.2.2</label><title>Domain</title></section><section id="sub-5.2.3"><label>5.2.3</label><title>Policy</title><section id="sub-5.2.3.1"><label>5.2.3.1</label><title>Zugriffssteuerungs-Policy</title></section><section id="sub-5.2.3.2"><label>5.2.3.2</label><title>Vereinbarungsprozess</title></section></section><section id="sub-5.2.4"><label>5.2.4</label><title>Rollen</title></section><section id="sub-5.2.5"><label>5.2.5</label><title>Policy-Repository</title></section><section id="sub-5.2.6"><label>5.2.6</label><title>Verzeichnis</title></section><section id="sub-5.2.7"><label>5.2.7</label><title>Authentisierung</title></section><section id="sub-5.2.8"><label>5.2.8</label><title>Prozess</title></section></section></section><section id="sub-6"><label>6</label><title>Policy-Vereinbarung</title><section id="sub-6.1"><label>6.1</label><title>Übersicht</title></section><section id="sub-6.2"><label>6.2</label><title>Identifizierung</title></section><section id="sub-6.3"><label>6.3</label><title>Zustimmung des Patienten</title></section><section id="sub-6.4"><label>6.4</label><title>Schutz von Patientendaten</title></section><section id="sub-6.5"><label>6.5</label><title>Informationsidentifizierung</title></section><section id="sub-6.6"><label>6.6</label><title>Speicherort der Information(en)</title></section><section id="sub-6.7"><label>6.7</label><title>Integrität der Information(en)</title></section><section id="sub-6.8"><label>6.8</label><title>Sicherheit</title></section><section id="sub-6.9"><label>6.9</label><title>Autorisierung</title></section><section id="sub-6.10"><label>6.10</label><title>Rollenstrukturen</title></section><section id="sub-6.11"><label>6.11</label><title>Zuweisungs- und Bestätigungsautorität</title></section><section id="sub-6.12"><label>6.12</label><title>Delegierungsregeln</title></section><section id="sub-6.13"><label>6.13</label><title>Gültigkeitsdauer</title></section><section id="sub-6.14"><label>6.14</label><title>Authentisierung von Benutzern/Rollen</title></section><section id="sub-6.15"><label>6.15</label><title>Zugriff</title></section><section id="sub-6.16"><label>6.16</label><title>Gültigkeitsdauer der Policy-Vereinbarung</title></section><section id="sub-6.17"><label>6.17</label><title>Ethos</title></section><section id="sub-6.18"><label>6.18</label><title>Sichere Zugriffsprotokollierung</title></section><section id="sub-6.19"><label>6.19</label><title>Auditprüfung</title></section><section id="sub-6.20"><label>6.20</label><title>Risikoanalyse</title></section><section id="sub-6.21"><label>6.21</label><title>Kontinuitäts- und Katastrophenmanagement</title></section><section id="sub-6.22"><label>6.22</label><title>Zukünftige Systementwicklungen</title></section></section><section id="sub-7"><label>7</label><title>Dokumentation</title></section><section id="sub-a"><label>Anhang A</label><title>Beispiel einer Textschablone für die Dokumentation (informativ)</title><section id="sub-a.1"><label>A.1</label><title>Allgemeines</title></section><section id="sub-a.2"><label>A.2</label><title>Beschreibung der Systeme und des Informationsaustauschs</title></section><section id="sub-a.3"><label>A.3</label><title>Administrativer Abschnitt der Dokumenttextschablone</title></section><section id="sub-a.4"><label>A.4</label><title>Auswertungsabschnitt der Textschablone für die Dokumentation</title><section id="sub-a.4.1"><label>A.4.1</label><title>Klassifizierungsschema</title></section><section id="sub-a.4.2"><label>A.4.2</label><title>Grundlegende Checklisten</title></section><section id="sub-a.4.3"><label>A.4.3</label><title>Sicherheitschecklisten</title></section><section id="sub-a.4.4"><label>A.4.4</label><title>Checklisten für Administratoren</title></section></section></section><section id="sub-b"><label>Anhang B</label><title>Beispiel einer Policy-Vereinbarung für den Informationsaustausch (informativ)</title><section id="sub-b.1"><label>B.1</label><title>Einleitung zur Vereinbarung</title></section><section id="sub-b.2"><label>B.2</label><title>Administrativer Teil</title><section id="sub-b.2.1"><label>B.2.1</label><title>An dieser Vereinbarung beteiligte Parteien</title></section><section id="sub-b.2.2"><label>B.2.2</label><title>Geltungsbereich der Vereinbarung</title></section><section id="sub-b.2.3"><label>B.2.3</label><title>Spezifizierung der Informationen</title></section><section id="sub-b.2.4"><label>B.2.4</label><title>Ansprechpartner</title></section><section id="sub-b.2.5"><label>B.2.5</label><title>Anmerkungen der Informationssicherheitsabteilung</title></section><section id="sub-b.2.6"><label>B.2.6</label><title>Sonstige Aspekte</title></section><section id="sub-b.2.7"><label>B.2.7</label><title>Unterschriften</title></section></section><section id="sub-b.3"><label>B.3</label><title>Beispiel für den Inhalt einer „Allgemeinen Policy-Vereinbarung“</title><section id="sub-b.3.1"><label>B.3.1</label><title>Geltungsbereich</title></section><section id="sub-b.3.2"><label>B.3.2</label><title>Begriffe</title></section><section id="sub-b.3.3"><label>B.3.3</label><title>Das System</title></section><section id="sub-b.3.4"><label>B.3.4</label><title>Informationsaustausch</title></section><section id="sub-b.3.5"><label>B.3.5</label><title>Örtliche Informationsverantwortungen</title></section><section id="sub-b.3.6"><label>B.3.6</label><title>Übertragung und Empfang der Informationen</title></section><section id="sub-b.3.7"><label>B.3.7</label><title>Sicherheit</title></section><section id="sub-b.3.8"><label>B.3.8</label><title>Datenschutz</title></section><section id="sub-b.3.9"><label>B.3.9</label><title>Verfügbarkeit</title></section><section id="sub-b.3.10"><label>B.3.10</label><title>Informationsverpflichtung</title></section><section id="sub-b.3.11"><label>B.3.11</label><title>Archivierung</title></section><section id="sub-b.3.12"><label>B.3.12</label><title>Verantwortlichkeiten</title></section><section id="sub-b.3.13"><label>B.3.13</label><title>Hindernisgründe</title></section><section id="sub-b.3.14"><label>B.3.14</label><title>Bedingungen der Vereinbarung</title></section><section id="sub-b.3.15"><label>B.3.15</label><title>Änderungen und Hinzufügungen</title></section><section id="sub-b.3.16"><label>B.3.16</label><title>Übertragung</title></section><section id="sub-b.3.17"><label>B.3.17</label><title>Streitfälle</title></section></section></section><section id="sub-annex.bibliography.int"><title>Literaturhinweise</title></section><section id="sub-na"><label>Nationaler Anhang NA</label><title>Literaturhinweise (informativ)</title></section></toc>