{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:16:41Z","timestamp":1750306601363,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2015,8,24]],"date-time":"2015-08-24T00:00:00Z","timestamp":1440374400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,8,24]]},"DOI":"10.1145\/2785592.2785599","type":"proceedings-article","created":{"date-parts":[[2015,8,11]],"date-time":"2015-08-11T18:24:13Z","timestamp":1439317453000},"page":"17-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Development and validation of the MedITNet assessment framework: improving risk management of medical IT networks"],"prefix":"10.1145","author":[{"given":"Silvana Togneri","family":"MacMahon","sequence":"first","affiliation":[{"name":"Dundalk Institute of Technology, Ireland"}]},{"given":"Fergal","family":"Mc Caffery","sequence":"additional","affiliation":[{"name":"Dundalk Institute of Technology, Ireland"}]},{"given":"Frank","family":"Keenan","sequence":"additional","affiliation":[{"name":"Dundalk Institute of Technology, Ireland"}]}],"member":"320","published-online":{"date-parts":[[2015,8,24]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Getting Started with IEC 80001: Essential Information for Healthcare Providers Managing Medical IT-Networks: AAMI","author":"Cooper T.","year":"2011","unstructured":"T. Cooper, Y. David, and S. Eagles, Getting Started with IEC 80001: Essential Information for Healthcare Providers Managing Medical IT-Networks: AAMI, 2011."},{"key":"e_1_3_2_1_2_1","unstructured":"West Health Institute \"The Value of Medical Device Interoperability - Improving patient care with more than $30 billion in annual health care savings \" 2013."},{"key":"e_1_3_2_1_3_1","volume-title":"Crossing the Quality Chasm: A New Health System for the 21st Century. Available: https:\/\/download.nap.edu\/catalog.php?record_id=10027","author":"Institute of Medicine.","year":"2001","unstructured":"Institute of Medicine. (2001). Crossing the Quality Chasm: A New Health System for the 21st Century. Available: https:\/\/download.nap.edu\/catalog.php?record_id=10027"},{"key":"e_1_3_2_1_4_1","volume-title":"ed","author":"President\u2019s Council of Advisors on Science and Technology (PCAST), \"Report to the President - Realizing the Full Potential of Health Information Technology to Improve Healthcare for Americans","year":"2010","unstructured":"President\u2019s Council of Advisors on Science and Technology (PCAST), \"Report to the President - Realizing the Full Potential of Health Information Technology to Improve Healthcare for Americans: The Path Forward,\" Executive Office of the President, Ed., ed, 2010."},{"key":"e_1_3_2_1_5_1","unstructured":"M. Logan and B. Patel \"Medical Device Interoperability - A Safer Path Forward \" AAMI Arlington VA2012."},{"volume-title":"August 2011 Symposium on the Role and Future of Health Information Technology in an Era of Health Care Transformation,\" The George Washington University2011","author":"Hamilton A.","key":"e_1_3_2_1_6_1","unstructured":"A. Hamilton, R. Nau, R. Burke, S. Weinstein, C. K. B. Dlatt, S. Fiore, et al., \"Summary of the August 2011 Symposium on the Role and Future of Health Information Technology in an Era of Health Care Transformation,\" The George Washington University2011."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2006.127"},{"key":"e_1_3_2_1_8_1","unstructured":"N. Milenkovich. (March 15 2013 16\/07\/2013). OCR issues new HITECH regulations Available: http:\/\/drugtopics.modernmedicine.com\/drugtopics\/news\/drug-topics\/health-system-news\/ocr-issues-newhitech-regulations"},{"key":"e_1_3_2_1_9_1","volume-title":"422 et al. Medicare and Medicaid Programs","author":"Centers for Medicare & Medicaid Services, \"\"42 CFR Parts 412, 413","year":"2010","unstructured":"Centers for Medicare & Medicaid Services, \"\"42 CFR Parts 412, 413, 422 et al. Medicare and Medicaid Programs; Electronic Health Record Incentive Program; Final Rule \", Health and Human Services Ed., ed, 2010."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1136\/bmj.320.7234.569"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1377\/hlthaff.20.6.64"},{"key":"e_1_3_2_1_12_1","volume-title":"Chronic care in America: A 21st century challenge,\" Princeton","author":"Hoffman C.","year":"1996","unstructured":"C. Hoffman and D. Rice, \"Chronic care in America: A 21st century challenge,\" Princeton, NJ: The Robert Wood Johnson Foundation, 1996."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCS.2013.69"},{"key":"e_1_3_2_1_14_1","volume-title":"14M networked medical devices to ship by","author":"Comstock J.","year":"2018","unstructured":"J. Comstock. (2013, 23\/01\/2014). 14M networked medical devices to ship by 2018. Available: http:\/\/mobihealthnews.com\/28295\/14m-networked-medicaldevices-to-ship-by-2018\/"},{"key":"e_1_3_2_1_15_1","volume-title":"ed","author":"Agency for Healthcare Research and Quality (AHRQ), \"Health IT for Improved Chronic Disease Management,\" Department of Health and Human Services","year":"2013","unstructured":"Agency for Healthcare Research and Quality (AHRQ), \"Health IT for Improved Chronic Disease Management,\" Department of Health and Human Services, Ed., ed, 2013."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-44.1.18"},{"key":"e_1_3_2_1_17_1","volume-title":"Advancing the Adoption of Medical Device \"Plug-and-Play\" Interoperability to Improve Patient Safety and Healthcare Efficiency","author":"Goldman J.","year":"2010","unstructured":"J. Goldman and S. Whitehead, \"Advancing the Adoption of Medical Device \"Plug-and-Play\" Interoperability to Improve Patient Safety and Healthcare Efficiency,\" 2010."},{"key":"e_1_3_2_1_18_1","volume-title":"Sept\/Oct 2010","author":"Venkatasubramanian K. K.","year":"2010","unstructured":"K. K. Venkatasubramanian, S. K. S. Gupta, R. P. Jetley, and P. L. Jones, \"Interoperable Medical Devices - Communication Security Issues,\" IEEE Pulse, vol. Sept\/Oct 2010, 2010."},{"key":"e_1_3_2_1_19_1","volume-title":"What Does IEC 80001-1 Mean to You?,\" 24x7 - Technology and Service Solutions for Biomeds","author":"Hampton R.","year":"2011","unstructured":"R. Hampton and R. Schrenker, \"What Does IEC 80001-1 Mean to You?,\" 24x7 - Technology and Service Solutions for Biomeds, 2011."},{"key":"e_1_3_2_1_20_1","volume-title":"Essential Collaboration for Improved Safety,\" AAMI.org","author":"Rakitin S. R.","year":"2009","unstructured":"S. R. Rakitin, \"Networked Medical Devices: Essential Collaboration for Improved Safety,\" AAMI.org, 2009."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-45.2.98"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-43.6.463"},{"key":"e_1_3_2_1_23_1","unstructured":"T. Gee. (2008 27\/1\/2012). Medical Device Networks Trouble Industry. Available: http:\/\/medicalconnectivity.com\/2008\/12\/18\/medical-devicenetworks-trouble-industry\/"},{"key":"e_1_3_2_1_24_1","volume-title":"Aiming for Patient Safety in the Networked Healthcare Environment,\" IT Horizons","author":"Eagles S.","year":"2008","unstructured":"S. Eagles, \"An Introduction to IEC 80001: Aiming for Patient Safety in the Networked Healthcare Environment,\" IT Horizons, vol. 2008, 2008."},{"key":"e_1_3_2_1_25_1","volume-title":"Healthcare and Public Health Sector,\" ed","author":"National Cybersecurity and Communications Integration Center, \"Attack Surface","year":"2012","unstructured":"National Cybersecurity and Communications Integration Center, \"Attack Surface: Healthcare and Public Health Sector,\" ed, 2012."},{"key":"e_1_3_2_1_26_1","unstructured":"D. Talbot. (2012 Computer Viruses Are \"Rampant\" on Medical Devices in Hospitals. MIT Technology Review. Available: http:\/\/www.technologyreview.com\/news\/429616\/computerviruses-are-rampant-on-medical-devices-in-hospitals\/"},{"key":"e_1_3_2_1_27_1","volume-title":"Baby's death spotlights safety risks linked to computerized systems,\" in Chicago Tribune, ed","author":"Graham J.","year":"2011","unstructured":"J. Graham and C. Dizikes, \"Baby's death spotlights safety risks linked to computerized systems,\" in Chicago Tribune, ed, 2011."},{"key":"e_1_3_2_1_28_1","volume-title":"ed","author":"Shuren J.","year":"2010","unstructured":"J. Shuren, \"Health Information Technology (HIT) Policy Committee Adoption\/Certification Workgroup - Testimony of Jeffrey Shuren, Director of FDA's Centre for Devices and Radiological Health,\" ONC, Ed., ed, 2010."},{"key":"e_1_3_2_1_29_1","volume-title":"Presentation from 19th Annual NCBA ConferenceSeptember 13","author":"Eagles S.","year":"2012","unstructured":"S. Eagles, \"IEC 80001: An Introduction,\" 80001-1 Experts, Presentation from 19th Annual NCBA ConferenceSeptember 13, 2012 2012."},{"key":"e_1_3_2_1_30_1","volume-title":"Roles, responsibilities and activities,\" ed","author":"Risk IEC","year":"2010","unstructured":"IEC, \"IEC 80001-1 - Application of Risk Management for IT-Networks incorporating Medical Devices - Part 1: Roles, responsibilities and activities,\" ed. Geneva, Switzerland: International Electrotechnical Commission, 2010."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-48.1.64"},{"key":"e_1_3_2_1_32_1","volume-title":"May\/June 2013","author":"Cooper T.","year":"2013","unstructured":"T. Cooper and K. Fuchs, \"The Wireless Challenge - Technology Risk Assessment In Healthcare Facilities,\" Biomedical Instruments and Technology, vol. May\/June 2013, 2013."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.2345\/0899-8205-45.4.295"},{"key":"e_1_3_2_1_34_1","volume-title":"Performing an assessment,\" ed","author":"IEC","year":"2003","unstructured":"ISO\/IEC, \"ISO\/IEC 15504-2:2003 - Software engineering \u2014 Process assessment \u2014 Part 2: Performing an assessment,\" ed. Geneva, Switzerland, 2003."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486046.2486074"},{"key":"e_1_3_2_1_36_1","unstructured":"ISO. (2014 November 3rd). The International Organization for Standardization. Available: http:\/\/www.iso.org\/iso\/home\/store\/catalogue_tc\/catalogue_d etail.htm?csnumber=37458"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017212.2017217"},{"key":"e_1_3_2_1_38_1","first-page":"2012","article-title":"Developing a Human-centred and Science-based Approach to Design: The Knowledge Management Platform Project","author":"Pascal A.","unstructured":"A. Pascal, C. Thomas, and A. G. L. Romme, \"Developing a Human-centred and Science-based Approach to Design: The Knowledge Management Platform Project,\" British Journal of Management, pp. n\/a-n\/a, 2012.","journal-title":"British Journal of Management"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01405730"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1240624.1240704"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"D. Tuffley \"Modelling Organisational Behavior with Process Reference Models \" 2012.","DOI":"10.5923\/j.se.20120202.01"},{"key":"e_1_3_2_1_42_1","first-page":"124","article-title":"Enhancing Benefits from Healthcare IT Adoption Using Design Science Research: Presenting a Unified Application of the IT Capability Maturity Framework and the Electronic Medical Record Adoption Model,\" in Design Science: Perspectives from Europe, ed","author":"Kenneally J.","year":"2013","unstructured":"J. Kenneally, M. Curley, B. Wilson, and M. Porter, \"Enhancing Benefits from Healthcare IT Adoption Using Design Science Research: Presenting a Unified Application of the IT Capability Maturity Framework and the Electronic Medical Record Adoption Model,\" in Design Science: Perspectives from Europe, ed: Springer, 2013, pp. 124-143.","journal-title":"Springer"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1555619.1555629"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017483.2017487"},{"key":"e_1_3_2_1_45_1","volume-title":"Being proactive: Where Action Research meets Design Research,\" presented at the Proceedings of the Twenty-Sixth International Conference on Information Systems","author":"Cole R.","year":"2005","unstructured":"R. Cole, S. Purao, M. Rossi, and M. K. Sein, \"Being proactive: Where Action Research meets Design Research,\" presented at the Proceedings of the Twenty-Sixth International Conference on Information Systems, 2005."},{"key":"e_1_3_2_1_46_1","first-page":"1","volume-title":"Action research and design science research\u2013seemingly similar but decisively dissimilar,\" in 17th European Conference on Information Systems","author":"Iivari J.","year":"2009","unstructured":"J. Iivari and J. Venable, \"Action research and design science research\u2013seemingly similar but decisively dissimilar,\" in 17th European Conference on Information Systems, 2009, pp. 1-13."},{"key":"e_1_3_2_1_47_1","volume-title":"Service management system requirements,\" ed","author":"IEC","year":"2011","unstructured":"ISO\/IEC, \"ISO\/IEC 20000-1:2011 - Information technology \u2014Service management Part 1: Service management system requirements,\" ed. Geneva, Switzerland, 2011."},{"key":"e_1_3_2_1_48_1","volume-title":"Code of Practice,\" ed","author":"IEC","year":"2012","unstructured":"ISO\/IEC, \"ISO\/IEC 20000-2:2005 - Information technology --Service management --Part 2: Code of Practice,\" ed. Geneva, Switzerland, 2012."},{"key":"e_1_3_2_1_49_1","volume-title":"Norfolk","author":"Office The Cabinet","year":"2011","unstructured":"The Cabinet Office, \"ITIL 2011 - Summary of Updates,\" ed. Norfolk, England: Crown Copyright, 2011."},{"key":"e_1_3_2_1_50_1","volume-title":"Switzerland","author":"Systems IEC","year":"2010","unstructured":"ISO\/IEC, \"ISO\/IEC TR 24774:2010 - Systems and software engineering \u2014 Life cycle management \u2014 Guidelines for process description,\" ed. Geneva, Switzerland, 2010."},{"key":"e_1_3_2_1_51_1","volume-title":"Germany","author":"Barafort B.","year":"2008","unstructured":"B. Barafort, A. Renault, M. Picard, and S. Cortina, \"A transformation process for building PRMs and PAMs based on a collection of requirements \u2013 Example with ISO\/IEC 20000,\" presented at the SPICE Nuremberg, Germany, 2008."},{"key":"e_1_3_2_1_52_1","first-page":"97","article-title":"Standalone software as an active medical device,\" in Software Process Improvement and Capability Determination, ed","author":"McHugh M.","year":"2011","unstructured":"M. McHugh, F. McCaffery, and V. Casey, \"Standalone software as an active medical device,\" in Software Process Improvement and Capability Determination, ed: Springer, 2011, pp. 97-107.","journal-title":"Springer"},{"key":"e_1_3_2_1_53_1","first-page":"10","article-title":"Guidance for Industry and FDA Staff - Recognition and Use of Consensus Standards","author":"Center for Devices and Radiological Health (CDRH)","year":"2007","unstructured":"Center for Devices and Radiological Health (CDRH), \"Guidance for Industry and FDA Staff - Recognition and Use of Consensus Standards,\" CDRH, Ed., ed, 2007, p. 10.","journal-title":"CDRH, Ed., ed"},{"key":"e_1_3_2_1_54_1","volume-title":"Guidance for Healthcare Delivery Organizations \", ed","author":"Risk TR","year":"2012","unstructured":"IEC\/TR, \"PD IEC\/TR 80001-2-4 - Application of Risk Management for IT-Networks incorporating Medical Devices - Part 2-4: Guidance for Healthcare Delivery Organizations \", ed. Geneva, Switzerland: International Electrotechnical Commission, 2012."}],"event":{"name":"ICSSP '15: International Conference on Software and Systems Process 2015","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"],"location":"Tallinn Estonia","acronym":"ICSSP '15"},"container-title":["Proceedings of the 2015 International Conference on Software and System Process"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2785592.2785599","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2785592.2785599","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:16:49Z","timestamp":1750227409000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2785592.2785599"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,8,24]]},"references-count":54,"alternative-id":["10.1145\/2785592.2785599","10.1145\/2785592"],"URL":"https:\/\/doi.org\/10.1145\/2785592.2785599","relation":{},"subject":[],"published":{"date-parts":[[2015,8,24]]},"assertion":[{"value":"2015-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}