Category: Information Security
-
NIST has released the fifth revision of the Security and Privacy Controls draft of Special Publication 800-53, now available for comments through September 12, 2017.
In this draft, NIST has incorporated state-of-the-practice controls based on new threat intel, plus changed the structure of the controls to make them more outcome-based. They’ve also consolidated and integrated privacy controls into security controls, and clarified the relationship between security and privacy to improve control selection.
-
OCR Tells Organizations to Step Up Phishing Scam Awareness -Employees Still Falling for Email Schemes, Leading to More Breaches
Employees are still falling for phishing scams that are leading to major breaches, including those related to ransomware attacks such as WannaCry, say federal regulators who are urging healthcare entities to step up their workforce training and awareness of email schemes.
-
Recent Events Increase the Importance of HIPAA Risk Analyses and HIPAA Policies
Recent events highlight the fact that threats to customer and patient data continue to increase. In recent months, government agencies, news outlets, and others have spent considerable time investigating and reporting on major worldwide ransomware attacks, including the “Petya” and “WannaCry” events. Moreover, numerous companies have reported significant malware or…
-
County Officials Didn’t Protect Computer Systems from Obvious Hacking Risks, Auditors Say
The Importance of a Security Program, that program headed by a CISO, and sitting at the C-level are all contributing factors to success. A Security plan/program IS a business plan no different than your financial plans. Even using a consultant or Virtual CISO (VCISO) is better than no plan at…
