In this paper, a methodology for determining the training needs of personne
l classes within health care establishments (HCEs) with respect to informat
ion systems security is discussed. This methodology, in way of an example,
is applied to a particular class of HCE personnel, namely managers, whose t
raining needs are derived. Further, the ISHTAR training course on informati
on systems security for HCE managers is evaluated against these requirement
s and improvements to it are proposed. (C) 2000 Elsevier Science Ireland Lt
d. All rights reserved.