ISMS
Risks, policies, audits and measures draw on the recorded systems. A risk therefore attaches to a real device rather than to a description someone once typed in.
Primary and standard care in the Südwestpfalz region
Städtisches Krankenhaus Pirmasens gGmbH provides primary and standard medical care for Pirmasens and the Südwestpfalz region. Across two sites, Pirmasens and Rodalben, it brings together 16 clinical departments and 10 centers.
A hospital of this size runs an IT landscape spanning medical devices, server rooms, network segments and workplaces, and it has to be available around the clock. isidaten serves as the shared platform here: information security and data protection build on the very inventory that operations maintain anyway.
A hospital cannot inventory its IT during quiet periods, because there are none. Keeping devices, racks, network addresses and recovery plans in separate lists means maintaining the same information several times and noticing discrepancies only once they cause trouble. What was needed was a foundation that collects the inventory itself rather than asking for it, and in which data center, network and emergency planning build on the same objects.
The scope follows day-to-day operations: first a reliable inventory, then data center, rule set and interfaces, and above them the management systems for security and data protection.
Risks, policies, audits and measures draw on the recorded systems. A risk therefore attaches to a real device rather than to a description someone once typed in.
A hospital processes health data, the special category under Article 9 GDPR. Records of processing, retention periods and policies therefore live on the same platform as the systems that actually hold that data.
Maintains hardware, system types, manufacturers and operating systems in one place. QR-coded labels connect the physical device with its record.
The agent collects the inventory itself and adds active scans, for example via SNMP on the network. The inventory becomes a measurement rather than a report.
Racks with power supply, PDUs and fuse mapping, plus IP address management in the same model. The server room does not live in a second spreadsheet.
The virtual infrastructure is connected and appears alongside physical devices in a single view.
Documents the rule set and reconciles it with the actual state of the devices. Rules nobody can explain any more, yet which still apply, surface in the process.
Reads the HL7 channels from the integration engine and maintains them in the interface register. Which data flows between which clinical systems is on record rather than in individual heads.
Backup concepts with documented restore tests, and recovery plans that build on the recorded devices rather than on descriptions.
Connects the existing Wazuh installation so that its hosts appear in the shared inventory.
Device, rack, network address and recovery plan all reference the same object. Opening a recovery plan shows the systems as actually recorded, not a transcribed list. And because the agent collects continuously, the inventory does not age between two stocktakes.
For an organization of this size, what matters is that the parts fit together:
Städtisches Krankenhaus Pirmasens shows that information security and data protection are not something maintained alongside operations. Risks, retention periods, firewall rules and recovery plans all point to the same systems the agent records anyway. The documentation therefore does not age between two audits.
In a no-obligation demo we show how isidaten simplifies your security and data protection processes.