Tuesday, 29 September 2015

New federal assessment tool highlights the importance of threat intelligence for financial institutions

By HP Security Strategist Stan Wisseman

In a previous post, I’ve encouraged use of frameworks to help determine a cybersecurity baseline capability and  roadmap to reach the goals for your information security programs. This summer, the Federal Financial Institutions Examination Council (FFIEC) introduced a new tool to assist financial organizations in following this approach.

In 2014, the FFIEC piloted a cybersecurity examination program at over 500 community financial institutions to evaluate their preparedness to mitigate cyber risks. On June 30th of this year, the FFIEC published a Cybersecurity Assessment Tool to provide ALL financial institutions with a repeatable and measureable process to inform leadership of their organization’s cyber risks (Inherent Risk Profile) and cybersecurity preparedness in relation to that risk (Cybersecurity Maturity). If the level of preparedness is inadequate, the organization may take action either to reduce the level of risk or to increase the levels of maturity (a “target” state). The Tool is mapped to both the FFIEC Information Technology Examination Handbook (FFIEC IT Handbook), as well as to the NIST Cybersecurity Framework.  Initially, the Tool will be voluntary but in the long term is expected to be incorporated into the FFIEC IT Handbook and used in regular examinations. The Tool identifies five domains, as shown above.

I’m going to focus on the Threat Intelligence & Collaboration domain in this post. I’m a strong proponent for threat intelligence sharing and am pleased that the FFIEC added this domain to their Assessment Tool. Timely sharing of intel about new or ongoing cyberattacks and threats should help avoid or minimize major breaches from an attack. I recognize that there’s still some controversy around private sector organizations sharing their threat intel with US Government agencies. Some of the potential negative consequences to this sharing was discussed at the 2nd annual Senior Executive Cyber Security Conference I attended in Baltimore earlier this month. Efforts are underway to craft legislation to address some of these concerns (see ICIT brief), though it’s unclear whether the US Congress will finalize these legislative efforts this year. Independent of the legislation, I still think that harnessing the collective wisdom of peer organizations we trust should be a win-win and is necessary to survive within our evolving threat landscape. The bad guys collaborate. We also need to.

Returning to the Assessment Tool, each domain and maturity level has a set of declarative statements (e.g., requirements) organized by the assessment factor. I’ve extracted some of the declarative statements from the Advanced and Innovative maturity levels for the Threat Intelligence & Collaboration domain below:

  • Threat intelligence is automatically received from multiple sources in real time.
  • A threat analysis system automatically correlates threat data to specific risks and then takes risk-based automated actions while alerting management.
  • Emerging internal and external threat intelligence and correlated log analysis are used to predict future attacks.
  • The institution uses multiple sources of intelligence, correlated log analysis, alerts, internal traffic flows, and geopolitical events to predict potential future attacks and attack trends.
  • IT systems automatically detect configuration weaknesses based on threat intelligence and alert management so actions can be prioritized.
  • Relationships exist with employees of peer institutions for sharing cyber threat intelligence.
  • A network of trust relationships (formal and/or informal) has been established to evaluate information about cyber threats.
  • A mechanism is in place for sharing cyber threat intelligence with business units in real time including the potential financial and operational impact of inaction.

I think the Tool encourages the building of effective threat collaboration partnerships through trust. HP has a taken a similar approach with its Threat Central service. Threat Central enables organizations to collaborate via a community-sourced security intelligence platform that incorporates dynamic threat analysis scoring to produce relevant, actionable intelligence to combat advanced cyber threats. Use of Threat Central can help you achieve some of the Advanced and Innovative declarative statements called for in the Assessment Tool.

Learn more about HP Enterprise Security.

Figure source: http://ift.tt/1FFBXhJ

 

View the original content and more from this author here: http://ift.tt/1KOHSwT



from health IT caucus http://ift.tt/1FFBX1e
via IFTTT

Johnson & Johnson, IBM Watson to create virtual coach apps for patients

IBM Watson and Johnson & Johnson will team up to create apps for consumers that will provide them with a virtual health coach.

Tech giant Apple also will lend a hand in development of the apps, which will be marketed to hospitals and other healthcare organizations that will then offer them to patients, according to the Wall Street Journal.

A prototype app to coach patients after knee replacement surgery will be released by J&J in the fourth quarter of 2015. The app will use IBM Watson’s computing and analytics platform, Apple design and J&J clinical knowledge to help improve patient outcomes and provide encouragement and treatment plans. IBM first announced it would be working with J&J in April. Article

View the original content and more from this author here: http://ift.tt/1FyC1QJ



from health IT caucus http://ift.tt/1iYsgkL
via IFTTT

How APIs can improve health data sharing

Gajen Sunthara, who spent a year as a Presidential Innovation Fellow with the Office of the National Coordinator for Health IT, says that patients must be at the center of the healthcare system and that application programming interfaces (APIs) can help, in a post to the Health IT Buzz Blog.

Sunthara (pictured) worked on applying APIs to improve data access, creating, among other things, a prototype personal health record (PHR) called myHealth API, which enables patients to aggregate their data from various providers across multiple data access points using the Fast Health Interoperability Resources (FHIR) framework. Sunthara previously served as principal software architect at the Innovation Acceleration Program at Boston Children’s Hospital and wrote his master’s thesis at Harvard on streamlining surgeon workflow using Google Glass,according to MedTech Boston.

Creating a single app that combines patient-generated health data from wearable devices and visuals from lab results, as well as medications, immunizations, genomics and other types of health data, can create a powerful, comprehensive view of a patient’s health, he says. His prototype, Sunthara notes, gives patients “drag-and-drop” control over their data and privacy

In addition, myHealth API allows patients to share their data with others. For instance, a Type 1 diabetes patient on a continuous glucose monitoring device could share that device information with a doctor through an API, he says.

Demand and participation eventually will drive use of open public APIs in healthcare for sharing information between entities, former U.S. Chief Technology Officer Aneesh Chopra said earlier this year, but providers must be more willing to take the plunge.

Previous fellows worked on improving Blue Button functionality, and one of the fellows working within the Department of Veterans Affairs recently spearheaded an initiative to create better prosthetic limbs.

View the original content and more from this author here: http://ift.tt/1KHLqnP



from health IT caucus http://ift.tt/1iYsgkJ
via IFTTT

BCBS Health Plans Contribute Cost, Quality Data to New Repository

Last week, the Blue Cross Blue Shield Association announced that all 36 independent BCBS plans will contribute information to a new repository designed to help lower costs and improve quality of care,Healthcare IT News reports (Miliard, Healthcare IT News, 9/25).

Database Details

The platform will be housed on the Blue Cross Blue Shield Axis database, which already includes information on:

  • $350 billion in annual claims
  • 36 million provider records; and
  • More than 700,000 BCBS patient reviews (Walsh, Clinical Innovation & Technology, 9/25).

The new information will include plans’ cost and quality data from the last three years, according to Maureen Sullivan, senior vice president of strategic services and chief strategy officer at BCBS.

According to Health Data Management, the new repository, which can be accessed through individuals’ health plan websites, is already live with cost and quality data and reviews in some markets.

BCBS plans to update the repository to also include:

  • Information on experience levels and other aspects of providers’ work, such as readmission and infection rates;
  • Explanations of specific procedures; and
  • Tools to help steer members toward better care and outcomes (Goedert, Health Data Management, 9/25).

Security Protections

Sullivan noted that information on the Axis database will be de-identified.

Further, BCBS CIO Doug Porter said the board has taken steps “to make sure that we’re scanning all of our environments for appropriate controls and to make sure that we don’t have any evidence of any compromises of our infrastructure” (Small, FierceHealthPayer, 9/24).

View the original content and more from this author here: http://ift.tt/1iYsgkT



from health IT caucus http://ift.tt/1KHLofz
via IFTTT

Health secretary to meet junior doctors’ leader over contract row

WEDI: ‘Robust’ Health IT System, Data Analytics Key to ACOs

An interoperable health IT infrastructure is key to the success of accountable care organizations, according to an issue brief released by the Workgroup for Electronic Data Interchange, EHR Intelligencereports (Murphy, EHR Intelligence, 9/28).

Details of Issue Brief

The paper was released by WEDI’s Payment Models Workgroup. It outlined barriers and best practices for ACOs and offered questions to consider when developing future guidance.

Among topics addressed in the issue brief were:

  • Data and analytics;
  • Health IT infrastructure; and
  • Population health management (Dvorak, FierceHealthIT, 9/28).

Findings

Overall, the report stated, “Successful financial, clinical, population health and risk management of an ACO is dependent upon a strong health IT infrastructure and an ability to exchange health data across disparate systems and setting.”

The issue brief noted that the health IT infrastructure for ACOs typically starts with electronic health records and then is layered with additional components that support:

  • Clinical documentation;
  • Data analytics;
  • Patient engagement and communication;
  • Revenue cycle management;
  • Risk management; and
  • Quality measurement and improvement.

Some ACOs also participate in health information exchanges (EHR Intelligence, 9/28).

According to the issue brief, interoperability becomes more important as ACOs mature and add such components (FierceHealthIT, 9/28).

However, the brief noted that “most ACOs are not currently able to seamlessly push or pull complete patient health data in an accessible and timely manner — and until they are able to do so, many organizations will find themselves fundamentally handicapped in their ability to meet operational objectives” (EHR Intelligence, 9/28).

Meanwhile, WEDI also said that ACOs increasingly will need new technologies to analyze the troves of health data collected from patients.

The authors said that ACOs will need to:

  • Consider the “pain points” for collection, measurement and exchange of health data; and
  • Determine whether there is a business case for implementing predictive and prescriptive analytics.

The brief noted that such health IT infrastructures and data analytics capabilities will be necessary to support ACOs’ population health management efforts (FierceHealthIT, 9/28).

View the original content and more from this author here: http://ift.tt/1KHLq7t



from health IT caucus http://ift.tt/1KHLnZb
via IFTTT

Monday, 28 September 2015

Cyber whistleblowing pivotal in ensuring corporate transparency and accountability in the IoT era

Whistle-blowing isn’t a new phenomenon, and has been recognized and protected under SOX, GLBA, Federal and State laws, as well as industry-specific regulatory frameworks. The Dodd-Frank Act has ensured additional protections for corporate officers who come forward with evidence of misconduct or wrongdoing, and created financial incentives for whistleblowers to report securities violations and fraud.

You may be aware of a recent decision by the Third Circuit Court of Appeals in FTC v. Wyndham Resorts, which affirmed FTC’s standing as a Federal cyber enforcer under the Court’s intentionally broad – and unanimous – interpretation of the “fair trade” doctrine. What this means is that the FTC will increase its scrutiny of cyber security issues which affect US commerce and involve US consumers, surely to add to its list of approximately 50 recent enforcement actions taken against a variety of firms thus far.

However, FTC can only act upon known issues. A breach affecting millions of consumers, such as the Wyndham case or the Target and Home Depot incidents, comes into FTC’s view only after the proverbial horse has left the barn. While FTC seeks to encourage responsible behavior through punitive action meant to act as a deterrent for the rest of the field, the retroactive nature of its action leaves much to be desired on the preventive side of the equation.

Despite a positive step in the right direction, the Commission’s post hoc enforcement scope creates a potential incentive for firms to conceal information security breaches at all costs in a bid to prevent additional scrutiny and likely punishment for failure to do adequately secure their information operations. In many cases, the firms are successful. As reported in the New York Times, a massive breach of a major industrial automation firm shortly after its $2-billion acquisition went unreported to the markets and regulators, remaining under wraps until a confidential customer memo was leaked to a well-known security blogger.

Wrapped in non-disclosure agreements and contract confidentiality clauses, manufacturers get to operate in secrecy, largely making the public disclosure of a breach a choice rather than an obligation (in cases not involving regulated consumer data such as credit cards and PII).

Transparency is difficult to come by in a field cloaked in what I call the “Three M’s” of cyber security: myth, mystique, and mystery. Confidentiality for confidentiality’s sake prevails throughout corporate organizations, stifling information sharing, discovery, and open debate – internal or external, – on cyber deficiencies and vulnerabilities.

CEO’s don’t want to hear about problems which they would be compelled to solve – if they actually heard about them. Integrity of internal controls, after all, is a serious matter well within the regulatory purview of the SEC. The logical answer, in the unscrupulous organizations at least, becomes rather obvious: keep the CEO and the Board from hearing about cyber issues they’d be forced to fix. With information security, that’s all too easy given the inherent complexity and difficulty in assessing the true state of cyber posture and maturity in global organizations.

This obfuscation doesn’t have to appear all that malicious, either. A simple omission, a confused statistic, an “honest mistake” in reporting threat or vulnerability data – all plausible enough to filter the information about known or suspected deficiencies in the enterprise security program.

How do we pierce this veil of corporate secrecy and obfuscation, designed to immunize and absolve the power structure while allowing cyber negligence to remain the accepted status quo? If internal reporting is suppressed, and those who speak out find themselves ostracized – or worse, – what channels are available for communicating internal issues tantamount to corporate misconduct and malfeasance?

The answer: Whistleblowing.

Encouraging and protecting those who come forward is essential to the functioning of markets and societies. Transparency, Integrity, and trust are non-negotiable. As our world continues to become “smarter”, more connected, more integrated, as our transactions become more distributed and rapid, as machine learning and automation become more mainstream by the day – it is fundamental we as consumers, and the regulators on our behalf, insist on total integrity and trustworthiness on the part of those who seek to populate our world with “smart” machines.

The manufacturers and suppliers competing for the lucrative space on our wrists, in our pockets, our kitchens, cars, and office buildings, must prove to us their technologies are safe, secure, and resilient before we allow them to take over our lives to the tune of 50 billion connected devices projected to surround us by the year 2020 (Gartner).

Whistleblowers are crucial in ensuring that no matter how complex an organization, how powerful or aloof the management, or how lucrative the business venture – consumers get to know the truth, and to make their choice in the marketplace based not only on the features of a product or service, but its maker’s trustworthiness and integrity.

Cyber whistleblowers have a pivotal role to play in the upcoming battle to connect our world. Let us encourage them and protect them.

In a recent article in CIO Magazine, the nation’s premier whistleblower attorney Debra S. Katz of Katz Marshall Banks provides an overview of the unique challenges faced by cyber whistleblowers, and the dangers for companies who retaliate against them:

View the original content and more from this author here:  http://ift.tt/1GbQEEi2985780/staff-management/changing-the-whistleblower-retaliation-culture.html



from health IT caucus http://ift.tt/1MAyGQA
via IFTTT