dokumendiregister.ee
OtsingAsutusedMCP
Otsing›Tervise- ja heaolu infosüsteemide keskus
Sissetulev kiriAvalik

Follow Up Compliance Check Report NCPeH MS-EE

Tervise- ja heaolu infosüsteemide keskus · 14. november 2023
Viit
1-6/389-1
Registreeritud
14. november 2023
Dokumendi liik
Sissetulev kiri
Adressaat
Euroopa komisjon
Saabumis/saatmisviis
e-post
Funktsioon
1 TEHIK tegevuse korraldamine
Sari
1-6 Asutuse juhtimise korraldamisega seotud kirjavahetus
Toimik
1-6/2023
Vastutaja
Aurelia Mihk (TEHIK, E-teenuste juhtimise osakond, Tervise talitus)

Failid

  • 📎FinalFCC_NCPeH-EE_ePA ePB.pdf488 KB

Sisu (failidest)

EUROPEAN COMMISSION DIRECTORATE-GENERAL HEALTH AND FOOD SAFETY Digital health Follow Up Compliance Check Report NCPeH MS-EE FinalFollowUpCC_NCPeH-EE_ ePA ePB Compliance Check Report for NCPeH- MS_EE/Follow Up | ePA ePB Date: 07/11/2023 Status: Final Version: 1.00 Author: Gartner Approved by: DG SANTE Reference number: FinalFollowUpCC_NCPeH-EE ePA ePB Public: DG SANTE external Confidentiality: Sensitive non-classified (SNC) Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 1 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) ß Document control information Property Value Title Follow Up Compliance Check Report NCPeH MS-EE Subtitle FinalFollowUpCC_NCPeH-EE_ ePA ePB Compliance Check Report for NCPeH-MS_EE/Follow Up | ePA ePB Author Gartner Project owner DG SANTE DG SANTE Project Konstantin Hypponen Manager Version 1.0 Confident Sensitive non-classified (SNC) Date 07/11/2023 Contract information Property Value Framework Contract DIGIT/2020/OP/0005 – BEACON Lot 1 Specific Contract BEACON000046 Document history The document author is authorised to make the following types of changes to the document without requiring that the document be re-approved: Editorial, formatting, and spelling; Clarification. To request a change to this document, contact the document author or project owner. Changes to this document are summarised in the table in reverse chronological order (latest version first). Version Date Description Action Section 1.00 07/11/2023 Final version I,R All 0.10 07/11/2023 Document submitted for review (SfR) I, R All 0.02 02/11/2023 Internal review I, R All 0.01 02/11/2023 Initial draft I All Action: I=Insert R=Replace Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 2 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Table of contents 1 MANAGEMENT SUMMARY ..........................................................................................................5 1.1 Objectives .............................................................................................................................................5 1.2 Target audience.....................................................................................................................................5 1.3 Scope.....................................................................................................................................................5 1.4 Readiness criteria ..................................................................................................................................5 1.5 Structure................................................................................................................................................5 1.6 Abbreviations & acronyms ...................................................................................................................6 1.7 Definitions ............................................................................................................................................6 2 FINDINGS AND RECOMMENDATIONS .....................................................................................8 2.1 Structure of the findings .......................................................................................................................8 2.2 General findings and Observations.......................................................................................................9 2.3 Legal and Organisational Domain ........................................................................................................9 2.4 Service Operations ..............................................................................................................................13 2.5 Information Security ...........................................................................................................................16 3 OVERALL CONCLUSIONS ..........................................................................................................18 4 CLOSING MEETING .....................................................................................................................20 Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 3 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) List of tables Table 11: Abbreviations and Acronyms ................................................................................................................... 6 Table 2: Definitions .................................................................................................................................................. 7 Table 3: Structure of the findings ............................................................................................................................. 8 Table 4: Status Observation a ................................................................................................................................... 9 Table 5: Status Finding 1 ........................................................................................................................................ 10 Table 6: Status Finding 2 ........................................................................................................................................ 11 Table 7: Status Finding 3 ........................................................................................................................................ 11 Table 8: Status Finding 4 ........................................................................................................................................ 12 Table 9: Status Finding 5 ........................................................................................................................................ 13 Table 10: Status Finding 6 ...................................................................................................................................... 14 Table 11: Status Finding 7 ...................................................................................................................................... 14 Table 12: Status Finding 8 ...................................................................................................................................... 15 Table 13: Status Finding 9 ...................................................................................................................................... 16 Table 14: Status Finding 10 .................................................................................................................................... 16 Table 15: Status Observation b............................................................................................................................... 17 Table 16: Status Finding 11 .................................................................................................................................... 17 Table 17: Status Finding 12 .................................................................................................................................... 18 Table 18: Overview of findings/observations and their status ............................................................................... 19 List of figures No table of figures entries found. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 4 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 1 MANAGEMENT SUMMARY On 29 September 2023, Gartner has received a request from the Estonian NCPeH to conduct a follow- up compliance check for services and ePA ePB. Gartner has provided the Agenda for the follow-up compliance check on 02 October 2023. This follow up compliance check was carried out remotely on 17 and 20 of October 2023. The objective of the compliance check was to assess the status of the findings from the initial compliance check. The compliance check team (CCT) was composed of two assessors. The subject matter experts from the Estonian NCPeH presented the progress and activities to the assessors, aimed to the mitigation of the findings. 1.1 OBJECTIVES The objective of the compliance check is to assess the NCPeH compliance with the eHDSI Requirements according to the eHDSI Readiness Criteria Checklist. This checklist is agreed by the eHealth Digital Service Infrastructure Member State Expert Group (eHMSEG). Particular attention was given to verify that appropriate policies and processes are in place, are communicated through the organisation, and are implemented in order to ensure the confidentiality, integrity and availability of information. 1.2 TARGET AUDIENCE The target audience for this document includes: ▪ NCPeH of MS-EE; ▪ DG SANTE. 1.3 SCOPE The scope of the compliance check covered the open findings and observations indentified during the operational compliance check, covering the organisation of the NCPeH and its activities related to the operation of ePrescription A and B service(s). 1.4 READINESS CRITERIA The criteria against which the NCPeH (and its service providers) was examined are the eHDSI Readiness Criteria Checklist1 V2.2. 1.5 STRUCTURE This document is organised as follows: Chapter 1 – Management Summary: provides the context of the compliance check and summary of the outcomes; 1 https://webgate.ec.europa.eu/fpfis/wikis/x/fPzzN Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 5 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Chapter 2 – Findings and Recommendations: details the findings and recommendations made during the Operational Compliance Check within the set scope of the compliance check, its criteria and objectives agreed to be achieved; Chapter 3 – Overall Conclusions: details the overall conclusions made during the Operational Compliance Check within the set scope of the compliance check, its criteria and objectives agreed to be achieved; Chapter 4 – Closing Meeting: presents a summary of the discussed topics during the closing meeting of the Operational Compliance Check; 1.6 ABBREVIATIONS & ACRONYMS For a better understanding of the present document, the following table provides a list of the principal abbreviations and acronyms used. Abbreviation/Acronym Definition BCDR Business Continuity and Disaster Recovery CBeHIS Cross-border eHealth Information System CCP Compliance Check Performer CMDB Configuration Management DataBase DPA Data Processing Agreement DPIA Data Protection Impact Assessment eHDSI eHealth Digital Service Infrastructure eHealth The use of information and communication technologies for health eHMSEG eHealth DSI Member State Expert Group EHR Electronic Health Record ICC Initial Compliance Check NC National Connector NCPeH National Contact Point for eHealth PIN Patient Information Notice eP-A ePrescription (and eDispensation) A eP-B ePrescription (and eDispensation) B PS-A Patient Summary A PS-B Patient Summary B SOP Service Operation Plan TEHIK Health and Welfare Information Systems Centreß Table 11: Abbreviations and Acronyms 1.7 DEFINITIONS For a better understanding of the present document, the following table provides a list of the principal terms used. Term Definition Country A Member State of Affiliation / Country of prescription Country B Member State of Treatment / Country of dispensation Finding A statement regarding the state of a conformity or non- conformity with the requirements, based on objective and verifiable evidence. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 6 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Observation A finding that does not indicate non-conformity with the requirements but suggests possible improvements related to the implementation of the requirements.4 Patient Summary Patient Summary provides information on important health related aspects such as allergies, current medication, previous illness, surgeries, etc. It is part of a larger collection of health data called Electronic Health Record (EHR). ePrescription ePrescription (and eDispensation) allows EU citizens to obtain their medication in a pharmacy located in another EU country, thanks to the online transfer of their electronic prescription from their country of residence where they are affiliated, to their country of travel. Table 2: Definitions Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 7 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 2 FINDINGS AND RECOMMENDATIONS For the purpose of this Follow Up Compliance Check (FCC) report, the terms ‘finding’ and ‘observation’ are used as defined in the Definitions section of this report. Conclusions of the report aim at highlighting the impact of the findings. This report focuses on the requirements and readiness criteria leading to findings, meaning requirements not fulfilled or readiness criteria not fully implemented. In contrast, requirements and readiness criteria for which the NCPeH demonstrated compliance are not reflected in the report. In addition to findings, the report also contains observations. An observation relates to an identified opportunity for improvement that does not strictly lead to a non-compliance with the eHDSI Readiness Criteria Checklist, but which is considered good practice by the compliance check team (CCT). To emphasise the distinction between findings and observations, observations are indicated with Roman numerals. 2.1 STRUCTURE OF THE FINDINGS Finding Original Finding Text Description Recommendation Original Recommendation Text Update FCC 05 Observations made during the compliance check October 2023 Status of the Status of the finding after the compliance check finding Table 3: Structure of the findings Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 8 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 2.2 GENERAL FINDINGS AND OBSERVATIONS a) Links in documentation to the former EC confluence pages Observation The documentation provided by the Estonian NCPeH contain obsolete links to Description the former EC confluence spaces (CEF Digital). In the second half of 2021, the information of the CEF Digital confluence spaces was transitioned to the new EC confluence space (https://webgate.ec.europa.eu/fpfis/wikis/x/noOhMg). This new eHDSI confluence space contains Operations, Semantic and Technical information. Due to this transition, several links to the former EC confluence spaces are obsolete. It has been observed that in the updated version of the Architecture document (v1.3) the links have already been updated. Recommendation Update links in documentation which still point to locations of the former EC confluence spaces, to the new EC confluence web pages (https://webgate.ec.europa.eu/fpfis/wikis/x/noOhMg). Associated finding(s): n/a Associated requirement: n/a Update FCC 20 The links got updated, as already noted in the report for the operational October 2023 compliance check. Status of the This observation can be closed finding Table 4: Status Observation a 2.3 LEGAL AND ORGANISATIONAL DOMAIN 1. [LO.4] Handling of the legislative changes impacting the provision of the cross-border services Finding TEHIK participates in meetings, organized by the Ministry (responsible for Description legislation), about proposed changes for the upcoming year. TEHIK can provide feedback based on the proposed changes and analyses done. Any work that needs to be done based on the proposed legislative changes, will be incorporated in an annual work plan. Although the process seems to be covered, this process or procedure for handling legislative changes is not documented. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 9 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Recommendation Document the process or procedure for handling legislative changes, taking into account activities already performed in relation to this criteria (e.g. participating in meetings on yearly proposed changes, incorporation in an annual work plan). Update FCC 20 The NCPeH has documented the Process (see LO.4_Legislation and development October 2023 process_EN). It covers aspects for new legislation (for a new development) or a new development (that needs new legislation). The documentation covers the existing process. The ministry also started to document their side of the process. From the NCPeH, when there is a development – the required legal impact is assessed (covering legal and developmental aspects). TEHIK has legal experts conducting this. Maintained by the owner of the development process -> Quality department. Status of the This finding can be closed. finding Table 5: Status Finding 1 2. [LO.5] Ensuring the protection of the cross-border health data coming from the other NCPeHs Finding The NIS directive (general information, official EU document) covers amongst Description others the cross-border collaboration and should be adapted in national legislation. Each Member State should identify “operators of essential services”, to which security requirements should be applied. It’s not clear whether the cross- border ePrescription services are identified by Estonia as “essential services”and therefore TEHIK being an “operator of essential services” for these services. Recommendation Determine if the operators of cross-border ePrescription services in Estonia are considered as “operators of essentials services” as defined in the NIS directive. Implement security measures accordingly. Update FCC 20 TEHIK was identified not be an operator of essential services. October 2023 Based on the definition of essential services, as defined by the ministry of interior, the organization does not meet the requirements to be classified as operator of essential services. While Emergency Care is considered ”essential services”, the cross-border services are not part of it (see definition of vital services on the webpage of the ministry of interior of Estonia). Status of the This finding can be closed. finding Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 10 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Table 6: Status Finding 2 3. [LO.5] Ensuring the protection of the cross-border health data coming from the other NCPeHs Finding The DPIA is updated whenever there is a need for it. During the compliance check Description it was mentioned that the need for updating the DPIA is ensured in the change management as well as in the incident management process. In the provided documentation (extract of TEHIKs confluence pages, containing amongst others process descriptions) this cannot be found. Recommendation Document the check to update the DPIA in the analysis done in the incident and change management process, as it was mentioned to be ensured during the compliance check. Update FCC 20 TEHIK has amended the documentation for change and incident management October 2023 stating that it must be assessed whether a change or incident leads to a DPIA (mostly in case of service changes or legal changes). Status of the This finding can be closed. finding Table 7: Status Finding 3 4. [LO.10] Provision of communication and training plans Finding Whenever a new staff member joins the NCPeH, the department manager is Description responsible for providing all kinds of (general) information. The service / project manager of cross-border services points the new staff member orally to the service passport, in which specific information can be found for the cross-border services. However, both are not documented in the staff onboarding process checklist or formalized in a welcome mail, in which is explained where to find what kind of information. The staff onboarding process covers very limited training, only the mandatory security training. Training on the usage of tools for the management of incidents, problems and changes is not included in the staff onboarding process. Only general manuals on Jira can be found on the TEHIK’s confluence pages. Recommendation Include instructions where to find what kind of information (like the roles & responsibilities on the QM confluence pages) in the onboarding process. Formalize directing new NCPeH staff to the service passport, in which specific information can be found for cross-border services, for example in an email they will receive with a link to the service passport. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 11 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Include training about the use of tools for the management of incidents, problems and changes in the staff onboarding process, including referral to the manuals or quick reference cards. Update FCC 20 The checklist has been moved to JIRA (previously was on Confluence). The October 2023 Checklist is put together by a specialist in TEHIK. With JIRA, the completion of these tasks can be tracked. The Tasks have to be approved by the hiring manager (which then gets reported to the HR department). The NCPeH demonstrated the checklist for a new employee during the compliance check from the view of the new employee and the services manager. TEHIK has also an onboarding day, which is mandatory for all new joiners (general information about the organization, building walkthrough, assignment of task). There is also a mentoring system in place. Depending on the position, there are additional trainings for individuals. Status of the This finding can be closed. finding Table 8: Status Finding 4 5. [LO.10] Provision of communication and training plans Finding Whenever a new staff member joins the NCPeH, the department manager is Description responsible for providing all kinds of (general) information. The service / project manager of cross-border services points the new staff member orally to the service passport, in which specific information can be found for the cross-border services. However, both are not documented in the staff onboarding process checklist or formalized in a welcome mail, in which is explained where to find what kind of information. The staff onboarding process covers very limited training, only the mandatory security training. Training on the usage of tools for the management of incidents, problems and changes is not included in the staff onboarding process. Only general manuals on Jira can be found on the TEHIK’s confluence pages. Recommendation Include instructions where to find what kind of information (like the roles & responsibilities on the QM confluence pages) in the onboarding process. Formalize directing new NCPeH staff to the service passport, in which specific information can be found for cross-border services, for example in an email they will receive with a link to the service passport. Include training about the use of tools for the management of incidents, problems and changes in the staff onboarding process, including referral to the manuals or quick reference cards. Update FCC 20 The checklist has been moved to JIRA (previously was on confluence). The October 2023 Checklist is put together by a specialist in TEHIK. With JIRA, the completion of Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 12 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) these tasks can be tracked. The Tasks have to be approved by the hiring manager (which then gets reported to the HR department). The NCPeH demonstrated the checklist for a new employee during the compliance check from the view of the new employee and the services manager. TEHIK has also an onboarding day, which is mandatory for all new joiners (general information about the organization, building walkthrough, assignment of task). There is also a mentoring system in place. Depending on the position, there are additional trainings for individuals, where the training on the tools is being addressed. . Status of the This finding can be closed. finding Table 9: Status Finding 5 2.4 SERVICE OPERATIONS 6. [OS.05] Organization of the communication processes with the other NCPeHs Finding For informal communications with other NCPeHs in case of issues, Slack is used. Description Slack formally was chosen as means of communication during test events. Usage of Slack for operational means of communication with other NCPeHs has risks (shadow IT risks: lost control and visibility). The risk includes security and regulatory noncompliance, and data leaks. Slack is not part of the approved tools within TEHIK to use for communications (like Skype for Business). Recommendation The IT (security) department should assess the use of “Open Slack”. Often shadow-IT software tools lack reliable backup, support, or business continuity controls and may be vulnerable for data leaks. Keep in mind that not every application requires instant, automated, cloud backup; 24 x 7 x 365 support; or a fail-over alternative in the event of an emergency. Assess the extent to which the shadow application may require additional (e.g. technical or policy) measures for safeguarding information shared via this tool. Update FCC 20 The information security department has provided a list of approved channels – October 2023 and slack was not on the list. But slack is used to contact experts in other MS. TEHIK has discussed this internally and stated to the Information Security department that Slack is used. It is now listed as a risk. It was agreed, that no sensitive data (patient data, security data etc.) is shared. This was originally done by e-Mail – starting this month (October 2023) a security exception process was implemented and the request was moved there (DELTA). Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 13 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) Status of the This finding can be closed. finding Table 10: Status Finding 6 7. [OS.06] Monitoring the Service Level Agreements (SLAs) with the ICT Service Providers/other entities managing the cross-border services Finding No specific agreements are made in the arrangements between the Ministry and Description TEHIK, other than minor requirements in legislation. TEHIK uses internal service levels only. For example for business continuity there are no defined and agreed service levels (like RPO, maximum allowable amount of data loss, and RTO, maximum allowable recovery time) for disaster recovery measures. Currently only an internal service level on back-up is documented. TEHIK has not formalized a waiver from the Ministry about not having an SLA between the Ministry & TEHIK, although there is email communication about this subject. Recommendation Define and agree service levels (like RPO, maximum allowable amount of data loss, and RTO, maximum allowable recovery time) for disaster recovery measures. Discuss with the Ministry the reason for and value of having agreed service levels in a broader sense than the minor requirements in the legislation, including RTO and RPO in case of a disaster. Otherwise formalize a waiver from the Ministry if the Ministry about not having a formal SLA between the Ministry & TEHIK and agreeing to TEHIK setting internal service levels. Update FCC 20 The discussion between the Ministry and TEHIK led to a waiver that an SLA October 2023 between the Ministry and TEHIK is not needed. Status of the This finding can be closed. finding Table 11: Status Finding 7 8. [OS.07] Management of the Testing activities Finding For testing changes as well as in disaster recovery tests, end-2-end testing is not Description fully implemented. End users are not included to test the changed or recovered (part of the) functionality of the cross-border service. For testing the implementation of a new wave, some pharmacies are visited to test if the functionality works as predicted. But it’s not documented which pharmacies participate in end user testing. Proper end-2-end testing cannot be done by the Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 14 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) NCPeH itself, due to the lack of a copy of the pharmacy systems for different reasons (too complex or supplier not willing to cooperate). Recommendation Implement end-2-end testing, including documenting which pharmacies (are willing to) participate in end user testing and pharmacy IS suppliers showing documented results of performed testing (like wave testing or tests done based on submitted changes). Implement end-2-end testing also when performing disaster recovery tests, by having end-users test the recovered (part of the) functionality of the cross-border service, including recording the results. Update FCC 20 The documentation was updated in the Services Passport (OS.7_Teenuse October 2023 pass_EN), see chapter 9. Additionally, 2 pharmacies agreed on supporting the tests if required. There is currently no possibility to legally contract this with the pharmacy system developer. Testings were conducted with the pharmacies already. The documentation in chapter 9 reflects an already existing process. Status of the This finding can be closed. finding Table 12: Status Finding 8 9. [OS.09] Handling the Configuration Management activities Finding Current CMDB information is fragmented and mostly in flat files, like MS Excel. Description This information is not integrated in the used process management tool (Jira). Because of this, trends analysis cannot be performed and supporting incident prevention and change impact analyses is very limited. Although this has already been reported (like in the recent ISKE audit or audits which are referred to in the ISKE audit) and the recommendation has been recognized by defining a project to implement a proper Configuration Management tool, the project has still not started because of not having any assigned resources Recommendation Implement a Configuration Management System (CMS) properly, since the current CMDB information is fragmented. Start the project to select / implement / transition to a new CMDB/CMS by assigning resources. Update FCC 20 The CMS/CMDB (JIRA Insight) is live since spring 2023. The implementation October 2023 is still ongoing – the help desk is using the CMDB and is also updating it. The procedures are not yet fully finalized since the NCPeH plans do develop/refine it ”on the go”. The CMDB is connected to JIRA. The NCPeH presented an internal Confluence Page, where the owners of the CMDB are listed (department and subject matter experts). Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 15 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) It was planned to finalize this by the end of 2023 but had to be postponed due to a major change of the IT Security System. Technical services are covered already (October 2023). Status of the This finding can be closed. finding Table 13: Status Finding 9 10. [OS.10] Planning and monitoring the capacity and availability of the cross-border services Finding Grafana and Zabbix are used for monitoring. Some thresholds are implemented Description and trigger alerts to Customer support as well as system administrators. It’s not clearly defined who is responsible for monitoring, it is a side task of multiple resources. There is no specific resource assigned for monitoring and acting on notifications, as a sort of ‘operator of the day’. Recommendation Clearly define who is responsible for monitoring and have a resource allocated for that, to be able to immediately intervene whenever an alert is triggered or even pro-actively whenever an indicator threatens to exceed. Update FCC 20 The NCPeH presented the Dashboard. The NCPeH has updated the job October 2023 descriptions of the System Administrators and the Service manager (who is responsible for the monitoring). The monitoring description in the Service Passport was updated (See chapter 6.2.1) Status of the This finding can be closed. finding Table 14: Status Finding 10 2.5 INFORMATION SECURITY b) [IS.06] Management of the Certificates Lifecycle Observation In the monitoring tool a threshold is implemented to notify 30 days before Description expiration of a certificate. An email is sent to the responsible for renewing the certificate and to customer support. A ticket in Jira still needs to be created manually, for recording activities (to be) performed. Recommendation If possible, automate the process of alerts on upcoming expiration of certificates even more by automatically creating a ticket, based on the alert from the Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 16 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) monitoring tool. Or create a reoccurring ticket for the renewal of a certificate, based on the certificate period. Update FCC 20 The NCPeH has updated the procedure in the Services Passport, chapter 6.2.2. October 2023 (OS.7_Teenuse pass_EN). A new monitoring has been created (in Prometheus) – tickets are not yet automatically created. This was assessed, but not followed up upon (as it was deemed to not provide additional value -> too many tickets). The Service Manager is responsible for this process. Status of the This Observation can be closed. Observation Table 15: Status Observation b 11. [IS.05] Management of the Information Security Incidents Finding The definition of security incidents according to ISKE is broad. Security incidents Description are registered when they pop-up. Vulnerabilities are firstly notified of via email and after being analysed they may be registered as security incident. In regard to the log4j vulnerability for example, the security incident was registered, but actions taken to solve this in the cross-border services domain are not linked to the security incident. Furthermore, the process of handling vulnerabilities is not documented. Recommendation Document the process of handling vulnerabilities and ensure the registration of a security incident is the starting point for further actions and investigations and link all subtasks or – incidents to the security incident. Update FCC 20 The information security department handles vulnerabilities. October 2023 If vulnerabilities are discovered, the report is sent to the service manager, service administrator and information security responsible and a ticket in JIRA is opened for it. In case a vulnerability impacts multiple services, one main incident is logged, and sub tasks are created. For Security incidents, the incident management procedure (IS.5_Intsidentide haldamise kord) defines Security Incidents in 3.14. An incident was shared during the compliance check, showing the documentation and the sub tasks added to the incident. Reports are being send to the Organization Director. Status of the This finding can be closed. finding Table 16: Status Finding 11 Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 17 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 12. [IS.07] Provision of Business Continuity and Disaster Recovery measures Finding Results of testing the DR procedures are not documented. Therefore, no trends Description can be analysed based on the tests performed. Furthermore, because of missing agreed service levels (RPO, maximum allowable amount of data loss, and RTO, maximum allowable recovery time), it cannot be checked if the recovery measures still ensure the service levels to be achieved or if improvements are needed. Looking at the provided disaster recovery plans, it seems last tests have been performed in 2019. Recommendation Document the results (including possible findings) of testing the DR measures / procedures. Analyse the findings and trends (in for example RTO) and identify and implement improvements (in actual measures or documentation like the BCP or DR plans) if applicable. Update FCC 20 The procedure states that the DR Plan must be retested depending on the SLA. October 2023 DR Tests are conducted twice per year. The Disaster recovery plan was updated (mainly to clarify and add more context/content). The NCPeH has provided the report on the last DR test (conducted 18.08.2023). Status of the This finding can be closed. finding Table 17: Status Finding 12 3 OVERALL CONCLUSIONS The table below provides a summary of the number of findings and their classifications per domain. Finding/ Control & Title Status Observation a General Observation: Links in documentation to Closed the former EC confluence pages 1 [LO.2] Organization of the NCPeH and the Closed National Infrastructure 2 [LO.4] Handling of the legislative changes Closed impacting the provision of the cross-border services 3 [LO.5] Ensuring the protection of the cross- Closed border health data coming from the other NCPeHs 4 [LO.5] Ensuring the protection of the cross- Closed border health data coming from the other NCPeHs Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 18 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 5 [LO.10] Provision of communication and Closed training plans 6 [OS.5] Organization of the communication Closed processes with the other NCPeHs 7 [OS.6] Monitoring the Service Level Agreements Closed (SLAs) with the ICT Service Providers/other entities managing the cross-border services 8 [OS.7] Management of the Testing activities Closed 9 [OS.9] Handling the Configuration Management Closed activities 10 [OS.10] Planning and monitoring the capacity Closed and availability of the cross-border services b [IS.6] Management of the Certificates Lifecycle Closed 11 [IS.5] Management of the Information Security Closed Incidents 12ß [IS.7] Provision of Business Continuity and Closed Disaster Recovery measures Table 18: Overview of findings/observations and their status All findings are now closed. We would like to thank the entire Estonian team for their openness, constructive and proactive collaboration. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 19 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC) 4 CLOSING MEETING The closing meeting was held on Friday, 20 October 2023 after the findings were reviewed. The NCPeH of EE acknowledged the oucome of this compliance check. Follow Up Compliance Check Report NCPeH MS-EE - FinalFollowUpCC_NCPeH-EE_ ePA ePB Page 20 / 20 Document version 1.0 dated 07/11/2023 Confidentiality: Sensitive non-classified (SNC)
Allikas: Tervise- ja heaolu infosüsteemide keskus dokumendiregister →
dokumendiregister.eeAsutusedEesti avalike dokumendiregistrite otsing · nimistu.ee andmetel