Abstract
Intro -- Table of Contents -- About the Author -- About the Technical Reviewer -- Acknowledgments -- Introduction -- Part I: Why Risk Assessment and Analysis? -- Chapter 1: Not If, but When -- Evolving Regulations and~Threat Landscape -- A New Kind of~Adversary -- Proliferation of~Ransomware -- Malware for~Sale -- It Costs Money When Things Go~Wrong -- The Approach Must Change -- Comply, but Not for~the~Sake of~Compliance -- Going on~the~Offensive -- Creating and~Trusting the~Process -- Summary -- Chapter 2: Meeting Regulator Expectations -- Introduction of~a~Proactive Audit Program -- Does Language and~Tone Lead to~Inaction? -- Why Does This Language Exist in~the~Guidance? -- Risk Analysis Methodology -- Scope and~Data Collection -- Threats -- Implement and~Assess Security Measures -- Vulnerabilities -- Risk Identification -- Likelihood and~Impact -- Other Risk Analysis Guidance and~Methodology -- HITRUST -- OCTAVE -- Choosing a~Framework Is Not Permanent -- Summary -- Chapter 3: Selecting Security Measures -- Cybersecurity Frameworks to~the~Rescue -- The NIST Cybersecurity Framework -- Identify -- Protect -- Detect -- Respond -- Recover -- Implementing Internal Controls Aligned with Subcategories -- The Cybersecurity Policy -- Measuring the~Cybersecurity Program -- Capability Maturity Model -- PRISMA -- Addressing Compliance Requirements -- HIPAA Security Rule -- Administrative Safeguards -- Physical Safeguards -- Technical Safeguards -- Summary -- Part II: Assessing and Analyzing Risk -- Chapter 4: Inventory Your ePHI -- Take a~Step Back and~Break Down the~Process -- Healthcare Provider Example -- Healthcare Plan/Payer Example -- Business Associate Example -- Create the~Asset List -- Summary -- Chapter 5: Who Wants Health Information? -- NIST Threat Guidance -- Inputs and~Threat Source Identification -- Types of~Adversaries State-Sponsored Attackers -- Organized Cybercriminals -- What Makes These Groups Sophisticated? -- Malicious Insiders -- Hacktivists -- Summary -- Chapter 6: Weaknesses Waiting to~Be~Exploited -- Predisposing Conditions -- Documenting Vulnerabilities -- Vulnerability Buckets Based on~the~NIST CSF -- Summary -- Chapter 7: Is It Really This Bad? -- Risk Statements -- Likelihood -- Impact -- Measuring Risk -- Creating the~Risk Register -- Risks Identified to~ePHI -- Graphical Representation of~Risks -- Reevaluation of~Risks Based on~a~Chaining of~Events -- Very High Risks -- High Risks -- Moderate -- Putting These Things into Business Terms -- Operational Impacts -- Financial Statement Impacts -- Summary -- Chapter 8: Increasing Program Maturity -- Moving from~Ad Hoc to~Operational -- Identify -- Protect -- Detect -- Respond -- Recover -- Addressing Very High and~High Risks -- Very High Risks -- Summary -- Chapter 9: Targeted Nontechnical Testing -- The Nontechnical {\textquotedbl}Eye Test{\textquotedbl} -- Access Management -- Privileged Access -- Reviewing Privileged Access -- Application Access -- Change Control -- Code and~Other Changes to~Functionality -- Patches -- How to~Test the~Change Management Process -- Training and~Awareness -- Incident Management -- Third-Party (Vendor) Risk Management -- Updating the~Risk Analysis and~Risk Register -- Summary -- Chapter 10: Targeted Technical Testing -- The Technical {\textquotedbl}Eye Test{\textquotedbl} -- Assessing Directory Services -- Data Loss Prevention -- Cloud Discovery and~Governance -- Vulnerability Identification and~Management -- Attack and~Penetration/Red Team Testing -- Testing Results and~Risk Updates -- Access Management Testing -- Data Protection Testing -- Vulnerability Management and~Attack Detection Testing -- Summary -- Part III: Applying the Results to Everyday Needs -- Chapter 11: Refreshing the~Risk Register Updating the~Risk Register -- Identify -- Protect -- Detect -- Respond -- Recover -- Risk Heat Map Updated -- Summary -- Chapter 12: The Cybersecurity Road Map -- Defining the~Cybersecurity Strategy -- The Three-Year Road Map -- Foundational -- How to~Measure Cybersecurity Capabilities Against~Foundational Requirements? -- Identify -- Protect -- Detect -- Respond -- Recover -- Focused Improvement -- Revisiting the~Kill Chain -- Training and~Awareness -- Baseline Configurations -- Boundary Security -- Monitoring End-User Activity -- Intelligence and~Analytics-Driven Security -- Threat Intelligence -- Machine Learning and~Artificial Intelligence -- Threat Analysis and~Reverse Engineering -- Decoys -- Addressing HIPAA Security Rule Requirements -- Summary -- Part IV: Continuous Improvement -- Chapter 13: Investing for~Risk Reduction -- Arbitrary Benchmarks and~Other Budget Fallacies -- Cybersecurity As~a~Percentage of~Total IT Spend -- How Much Does Cybersecurity Cost? -- Remembering the~Human Factor of~Budgeting -- A Risk-Based Approach to~Cyber Budgeting -- The Updated Risk Analysis -- Cybersecurity Objectives and~Road Map -- Investing in~the~Fundamentals -- Targeted Improvements of~the~Program -- Intelligence and~Analytic-Driven Program -- Summary -- Chapter 14: Third-Party Risk: Beyond the~BAA -- Analyzing Third-Party Risk -- Governing Third-Party Risk Management -- Evaluating Security Controls -- Gathering Relevant Information -- SOC 2-Common Criteria -- CC 1.0: Common Criteria Related to~Organization and~Management -- CC 2.0: Common Criteria Related to~Communications -- CC 3.0: Common Criteria Related to~Risk Management and~Design and~Implementation of~Controls -- CC 4.0: Common Criteria Related to~Monitoring Controls -- CC 5.0: Common Criteria Related to~Logical and~Physical Access Controls -- CC 6.0: Common Criteria Related to~System Operations CC 7.0: Common Criteria Related to~Change Management -- ISO Certification -- HITRUST Certification -- Cybersecurity Questionnaire -- Gathering Additional Details -- Evaluate Security Controls and~Identify Risks -- Evaluating Threats to~ePHI Held at the~Third Party -- Identifying Vulnerabilities at the~Third Party -- Measuring Risk at the~Third Party -- Risk Statements -- Third-Party Risk Integration -- A Word on~Cloud Solutions -- Summary -- Chapter 15: Social Media, BYOD, IOT, and~Portability -- Social Media -- Business Needs vs. Risks -- Danger Lurks Around the~Corner -- Addressing Social Media Risks -- Internet of~Things (IoT) -- Bring Your Own Device (BYOD) -- Portable Devices -- Summary -- Chapter 16: Risk Treatment and~Management -- Creating the~Risk Treatment and~Management Plan -- Very High Risks -- High Likelihood and~Very High Impact Risks -- Moderate-High Likelihood and~Moderate Impact -- Moderate-Moderate Likelihood and~Very High Impact -- Moderate-Moderate Likelihood and~High Impact -- Summary -- Chapter 17: Customizing the~Risk Analysis -- Risk Analysis Parameters -- Likelihood -- Assessing the~Level of~Maturity -- Assigning Impact Values -- Very Low -- Low -- Moderate -- High -- Very High -- Risk Analysis Walkthrough: Two Examples -- Access Management Risk -- Evaluating Likelihood -- Evaluating Impact -- Monte Carlo Simulations of~Likelihood and~Impact -- Insecure Development and~Quality Assurance Environments -- Evaluating Likelihood -- Evaluating Impact -- Monte Carlo Simulation Assumptions -- Comparing the~Results -- Summary -- Chapter 18: Think Offensively -- The Risk Analysis Journey -- Threat Actors and~Scenarios -- Vulnerabilities -- Impact -- Get Offensive -- The HIPAA Compliant Program -- Take Ten Minutes Each Day and~Get the~Process Started -- Month One: Identifying All Instances of~ePHI -- Month Two: Vulnerabilities Month Three: Threat Actors and~Vulnerability Mapping -- Month Four: Measure the~Likelihoods -- Month Five: Measure the~Impacts -- Month Six: Identify Cybersecurity Controls -- Get Better -- Summary -- Appendix A NIST CSF Internal Controls -- Appendix B NIST CSF to~HIPAA Crosswalk -- Identification: Asset Management -- Identification: Business Environment -- Identification: Governance -- Identification: Risk Assessment -- Identification: Risk Management -- Protect: Access Control -- Protect: Awareness and~Training -- Protect: Data Security -- Protect: Information Protection -- Protect: Maintenance -- Protect: Protective Technology -- Detect: Anomalies and~Events -- Detect: Continuous Monitoring -- Detection: Detection Processes -- Response: Response Planning -- Response: Communications -- Response: Analysis -- Response: Mitigation -- Response: Improvement -- Recovery: Recovery Planning -- Recovery: Improvements -- Recovery: Communications -- Appendix C Risk Analysis Templates -- Risk Analysis Template -- Instances of ePHI -- Threats -- Vulnerabilities -- Risk Ratings and Graph -- Risk Heat Map -- Third-Party Risk Template -- Cover Sheet -- Threats -- Potential Vulnerabilities -- Third-Party Controls -- Third-Party Risk Analysis -- Index
Cite
CITATION STYLE
Thompson, E. C. (2017). Building a HIPAA-Compliant Cybersecurity Program. Building a HIPAA-Compliant Cybersecurity Program. Apress. https://doi.org/10.1007/978-1-4842-3060-2
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.