How to Build a Healthcare Cybersecurity Roadmap

15.0K views
•
February 16, 2017
by
RSAC Cybersecurity
YouTube video player
How to Build a Healthcare Cybersecurity Roadmap

TL;DR

Build a healthcare cybersecurity roadmap by adapting the NIST Cybersecurity Framework to architecture domains such as networks, identity and access management, applications, data, and monitoring. Assess gaps, define a future state, balance protection with detection and response, integrate capabilities across domains, and replace reactive product buying with governed tactical and strategic initiatives.

Transcript

Good morning, everyone. Thank you for, uh, joining my session this morning. Uh, my name is Nick Yu, and I work as a chief security architect for a, uh, large healthcare IT company. And, uh, this morning I wanna share with you how we went about building cybersecurity roadmap using the NIST framework. I wanna especially highlight how we tailor this f... Read More

Key Insights

  • Healthcare records are valuable targets because they can combine identity information, complete health histories, and payment details in a single record. Expanding electronic access and information exchange across healthcare entities also creates a complex environment that organizations must protect while meeting regulatory and compliance requirements.
  • Compliance is a useful security foundation, but completing requirements does not prove that an organization can identify its most important assets, recognize relevant attackers, understand their techniques, detect incidents promptly, contain compromises, or restore affected capabilities after an event.
  • Reactive security programs are driven by compliance demands, vendor messaging, new threats, and vulnerability deadlines. This pattern encourages organizations to add products and patches continually without first establishing a coherent target architecture, governance process, lifecycle plan, or clear measure of improved security posture.
  • Security tools are operational commitments because products require configuration, maintenance, integration, and ongoing support after purchase. A large collection of overlapping tools can increase complexity and cost, especially when business units make separate decisions and products reach the end of their supported lifecycle without planned replacements.
  • Basic security weaknesses are responsible for a large share of attacks described in the presentation. Default or weak passwords and recurring attack patterns show why organizations should strengthen foundational controls instead of directing disproportionate investment toward sophisticated prevention technologies that may not address common exposure paths.
  • The NIST Cybersecurity Framework is suitable for architectural planning because it consolidates controls associated with recognized standards while remaining a flexible guideline. Organizations can tailor its functions, categories, and subcategories to their environment instead of treating adoption as a compliance checkbox exercise.
  • The NIST functions form an operational security cycle that begins with understanding protected assets and applying safeguards. The framework then addresses detecting incidents, responding quickly enough to contain them, and recovering compromised capabilities before an intrusion can spread to an organization's most sensitive assets.
  • Enterprise security architecture works best when capabilities are organized into defined domains such as networks, identity and access management, applications, data, and monitoring and analytics. Each domain should contain appropriate protection, detection, and response capabilities, while technologies across domains should integrate rather than operate as isolated products.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can healthcare organizations build a cybersecurity roadmap with NIST?

A healthcare organization can begin with the NIST Cybersecurity Framework functions, categories, and subcategories, then tailor them to its enterprise architecture. It should identify assets, assess existing safeguards, locate security gaps, define a future-state architecture, and establish tactical and strategic initiatives. Capabilities should be mapped into domains such as networks, identity, applications, data, and monitoring, with protection, detection, response, and integration considered throughout.

Q: Why should the NIST Cybersecurity Framework be treated as a guideline?

The framework is valuable as a guideline because an organization can adapt its methodology to its own environment instead of reducing security to a checkbox exercise. The healthcare firm retained the NIST content, categories, and subcategories while adding an architecture-driven approach. That tailoring supported gap identification, future-state design, and initiative planning while allowing existing controls associated with established standards and certifications to serve as a practical starting point.

Q: Why is a compliance-driven security strategy insufficient?

Compliance can provide essential baseline controls, but it does not automatically answer whether security posture has improved or whether defenses match actual threats. A stronger strategy also asks which assets require protection, who the relevant threat actors are, what techniques they use, and whether prevention and detection mechanisms are adequate. Without those answers, organizations may satisfy requirements while remaining reactive, fragmented, and unable to measure meaningful risk reduction.

Q: What problems result from buying too many security products?

Each security product requires care, configuration, maintenance, integration, and eventual replacement. When teams purchase tools independently in response to compliance requirements, vendor claims, or emerging threats, the result can be overlapping capabilities, weak standards, limited governance, and products that do not communicate effectively. The organization described in the presentation also discovered unsupported or aging products without an established refresh plan, demonstrating the need for lifecycle and ownership discipline.

Q: How should security capabilities be organized across architecture domains?

Security capabilities should be grouped into domains that reflect the enterprise environment, including networks, identity and access management, applications, data, and monitoring and analytics. Each domain should be sufficiently self-contained to contribute protection, detection, and response capabilities. At the same time, the domains must not become isolated silos. Their capabilities and technologies should integrate so that information and defensive actions can operate coherently across the broader architecture.

Q: Why should healthcare security focus on foundational controls?

The presentation argues that many attacks rely on ordinary weaknesses and recurring patterns rather than highly difficult techniques. Examples include default or weak passwords, malware, web attacks, and distributed denial-of-service activity. Organizations should therefore verify that basic safeguards are consistently implemented before assuming sophisticated prevention products will solve their risk. Foundational security, appropriate detection, and the ability to contain incidents may address more realistic exposure than continual tool acquisition.

Q: What does the NIST identify, protect, detect, respond, and recover model accomplish?

The model connects security planning with the full incident lifecycle. Identify establishes which assets and capabilities matter. Protect applies safeguards to those assets. Detect determines whether an incident has occurred. Respond supports rapid containment so an intrusion does not reach sensitive organizational assets. Recover focuses on restoring capabilities that were compromised. Together, these functions help an organization evaluate security as an operating system of coordinated capabilities rather than a collection of prevention products.

Q: How can an organization move from reactive security to architecture-led planning?

The organization can inventory its technologies, assess gaps against the NIST framework, examine relevant threats and protected assets, and define a future-state architecture before purchasing additional products. It should introduce governance, common standards, integration requirements, lifecycle planning, and clear ownership across business units. Tactical initiatives can address immediate weaknesses, while strategic initiatives move the environment toward the target architecture and create a defensible basis for evaluating whether security posture is improving.

Summary & Key Takeaways

  • Healthcare IT became difficult to secure as electronic health records increased the accessibility and exchange of sensitive information among physicians, hospitals, pharmacies, and payers. Medical records may contain Social Security numbers, birth dates, health histories, and payment information, making healthcare organizations attractive targets while regulatory and compliance obligations continue shaping their technology environments.

  • Compliance programs and industry certifications established basic security controls, but they also contributed to reactive practices. The organization accumulated products in response to requirements, vendor messaging, emerging threats, and newly discovered vulnerabilities. Many tools required configuration, maintenance, integration, and replacement planning, yet governance, common standards, lifecycle management, and total cost analysis were insufficient.

  • The organization adopted the NIST Cybersecurity Framework as a flexible guideline rather than a checklist. It mapped framework categories and subcategories into enterprise architecture domains, assessed gaps, designed a future state, and planned tactical and strategic initiatives. Each domain was expected to support protection, detection, and response while integrating effectively with capabilities elsewhere in the architecture.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚