insuranceciooutlook
9 Jan-Feb 2017environments, especially around cloud access security brokers (CASB) and identity and access management (IAM) technology. This is because of the hybrid nature of on-premise environments being interconnected to multiple large cloud providers and increasingly more connected IoT. We have to look for the best options to maintain and enforce efficient policies in all the environments in a seamless and transparent way.Over the course of my career, I have learned three lessons. First, healthcare information security is different. To effectively apply enterprise information security to a healthcare organization, you really have to understand healthcare, particularly the physician workflow and patient safety impact of security changes.Second, training and awareness efforts remain highly important and effective. Credentialed users (or the valid credentials of users) are the start of a majority of data breaches. Rather than approaching end users as the root cause of the problem, you need to enlist their help as the first line of defense and first responders. It really comes down to an organizational culture of security being everyone's responsibility, not just the niche of Information Security or even the IT department.The third lesson has to do with the evolution of the CISO's role within an organization. With the advancement of the role to the C-suite comes newer responsibility of decision-making. The business acknowledges the value in integrating good security up front and top down rather than as an afterthought in business partner relationships, vendor management, system development, and technology procurement. Integration is Key to Cost-efficiencyThe best way technology can be used to mitigate rising security solution costs is to integrate multiple solutions into one and reduce the human interface requirement. Combine into one system the capabilities to protect network resources, monitor, and alert on network traffic, and then remediate and recover network assets to minimize downtime. However, the complexity of that single system should not demand an inordinate increase in personnel to run the solution, as it just substitutes one cost with another.Additionally, security solutions can automate manual tasks and learning to more quickly assimilate and take action on threat intelligence streams against data that is gathered within the environment. Big data and artificial intelligence (AI) represent exciting opportunities for creating force multipliers versus each new solution requiring a manpower tradeoff or increased personnel to operate, refine, and orchestrate.I think you need to answer two questions every day--So what? And, what else? When we do a periodic assessment of our security tools inventory, one of the key components is looking at the data the devices give us. They all generate gobs of data in reports. Does any of that data actually measure added security or reduced risk? The tough task is determining "so what?" At every level of analysis (tactical, operational, strategic) you have to know the answer. The "what else?" question measures the value we are getting now and forecasts additional capabilities we can gain from our tools. Recently, we embarked on a tools rationalization view of our environment against the Center for Internet Security (CIS) Controls for Effective CyberDefense to help us address where we have adequate assets and where we have gaps. The gaps are being addressed via a security roadmap as well as addressing "what else" our current tools can do to realize additional capabilities or integrate into other tools to improve the overall coverage. In these ways, we drive more value out of our security solutions and, by extension, our security solution suppliers. One device that can protect, detect, and recover up and down the entire open systems interconnection (OSI) model is innovation I am interested in seeing
< Page 8 | Page 10 >