The Field Report
There are 18,000 banking institutions in the U.S., and somebody has to blog about their breaches, concerns and security successes.

July 27, 2010 - Jack Daniel
Comments (1) Read All Posts (6)Rather than taking a piecemeal approach to security, hospitals, clinics and others should create what I call an electronic health record security ecosystem.
The most critical element in building a security ecosystem is the risk assessment. The time to complete one is |
The ecosystem approach enables organizations to continually assess their security posture against changes in their business and the industry. Properly built ecosystems protect many walled and non-walled environments, including information collection, storage and exchange. Applying a "right-sized" best practices approach to various security borders requires the appropriate blend and focus on people, policies and processes, and the correct portfolio of security technologies.
Here's a guide to the key steps:
Step 1: Understand the Security and Privacy Landscape
Before building a security ecosystem, security professionals must first review the high-level components of their security and privacy landscape. Several regulatory concerns must be addressed. Chief among them are:
Step 2: Conduct a Risk Assessment
The risk assessment process includes analyzing best practice frameworks, quantifying risks and identifying gaps to create a program roadmap. Properly followed, the outcome of this process is a comprehensive assessment of an organization's security program, an actionable set of recommendations and a clear roadmap and plan for remediation. Key steps are:
Step 3: Create a Governance and Security Policy These policies are critical to gaining executive buy-in and building a successful security ecosystem. Reviewing resources, strategic alignment and risks enables organizations to understand whether they can meet their goals.
Policy development should address key areas including:
Every organization should have clear accountability for the processes, policies and controls to trace actions to their sources and ensure technical and operational security of the intended work.
Step 4: Develop and Implement Procedures
Procedure development identifies standards for what needs to be in place. Procedures create processes for both operations and technology to guide security implementation. They are a critical component for information and enforcement in a security program. The bottom line is this: The most critical element in building a security ecosystem is the risk assessment. The time to complete one is now.
Daniel is the security team leader and principal consultant for Concordant, which provides healthcare IT consulting services, specializing in ambulatory EHR adoption and implementation. He has extensive experience as an information security professional with expertise in regulatory compliance, governance, security engineering and security awareness training. He is a member of the Information Systems Audit and Control Association and the International Information Systems Security Certification Consortium.

National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
NIST SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable..Next Topic