Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/28/2014
12:23 PM
John B. Dickson
John B. Dickson
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv

What Scares Me About Healthcare & Electric Power Security

Both industries share many of the same issues as enterprises. But they also have a risk profile that makes them singularly unprepared for sophisticated threats

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
jdickson782
50%
50%
jdickson782,
User Rank: Author
10/31/2014 | 5:29:24 PM
Re: Accounting standard or security standard?
My overarching thought here is that every organization should have a general controls/ISO-27002 security assessment, but that this is only a starting point. More sophisticated organizations have multiple layers of security defense and do much more focused security testing to validate what's been implemented.
jdickson782
50%
50%
jdickson782,
User Rank: Author
10/31/2014 | 5:26:29 PM
Re: Healthcare
See my comments to Gary's post - unfortunately, there will have to be more high-profile losses before healthcare providers rate security up there with other risk management issues.
jdickson782
50%
50%
jdickson782,
User Rank: Author
10/31/2014 | 5:25:15 PM
Re: Stop signs are installed AFTER a traffic accident occurs.
Sadly, I think you are correct here.  Absent of more high-profile losses, many in the healthcare industry will view the threat as remote.  My thoughts in the article were really based on ~20 years reviewing healthcare organizations and their high-level posture.
Gary Scott
50%
50%
Gary Scott,
User Rank: Strategist
10/31/2014 | 4:31:27 PM
Stop signs are installed AFTER a traffic accident occurs.
Action follows demand.  Until a majority of patients are negativley affected by a security issue nothing will be done.
rzw122
50%
50%
rzw122,
User Rank: Apprentice
10/29/2014 | 5:50:46 PM
Healthcare
OMG! I let out a yelp of agreement as I sprang from my seat and began clapping after reading this commentary. This is an affirmation that I've long needed in my seemingly-solo quest to help medical practitioners understand the importance and value of securing their networks. Conversations with this those in this industry- even about minor perimeter security measures- are often met with shrugs or blank stares, but even more maddening are the reactions of whatever tech staff that physicians have managed to loosely piece together. These individuals are an enigma, for it is they who are the ones that we might expect to hold a more profound understanding of the consequences of lax security, or, in some cases, no security at all. Thank you for this piece.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
10/29/2014 | 1:17:17 PM
Re: Accounting standard or security standard?
@Ed Telders: Agreed, and that is precisely why I have asked for either the SAS 70 or SSAE 16. I wanted to know how religiously they followed their controls and to judge their "level of maturity" as you had put it.
Ed Telders
50%
50%
Ed Telders,
User Rank: Apprentice
10/29/2014 | 11:41:23 AM
Re: Accounting standard or security standard?
The SAS 70 was sunsetted in 2011 and replaced by the SSAE16 auditing standards.  They come in three flavors in the SOC1, SOC2, and SOC3 audit reports.  For each of them the reports can be a Type 1 or a Type 2.  In a Type 1 the audit simply looks at documentation and assesses them based on policies and statements, the Type 2 is where the controls are actually tested.  Naturally you want the Type 2.  Also the SOC1 is essentially the same as the old SAS 70 in that it is used to measure financial transactions and financial reporting.  Many have used that in the past as a means to assess vendors for security, although the SAS 70/SOC1 was never intended to be a security tool.  It does not assess the CIA triad nor does it look at actual enterprise security, only a subset of that.  The SOC2 Type 2 is the tool you want to look for to actually make a determination of the security posture and maturity of a vendor you're considering.  I would also recommend you review the detailed findings and managment responses to those findings to determine if any of them are of concern to you.  If for example, the audit has a finding detecting servers that are not patched, managment then responds that they have remediated them since the audit field work it sounds pretty reasonable.  Unless the number of servers found unpatched is larger than a reasonable number (ex. 100 out of 500 total) which would indicate a material procedural problem with that vendors processes.  The details can be a gold mine of information that can help you make a solid decision between vendors.  And yes the smaller "boutique" vendors and "startups" frequently haven't created this level of maturity that would be more typical of larger well-established providers, so buyer beware.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
10/29/2014 | 11:29:30 AM
Re: Accounting standard or security standard?
Yes, SAS 70 is an auditing standard designed to perform an in-depth examination of control objectives and activities. During the performance of this audit by an independent accounting and auditing firm, an organization's written controls are verified by auditing the actual activities related to the controls. These controls also include those specific to Information Technology and related processes. What I wanted to see was whether or not potential business partners actually practiced the controls they had in place, especially those specific to IT.
DBAJRACHARYAN/A
50%
50%
DBAJRACHARYAN/A,
User Rank: Apprentice
10/29/2014 | 9:55:04 AM
Accounting standard or security standard?
Is not SAS70 an auditing standard? Are you looking for data security standard or financial stability of the organization?
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
10/29/2014 | 9:03:49 AM
Re: public safety
The theft of personal information in healthcare has been pretty well documented (the prices for PII on the black market are at a record high). But my guess it will ake some life threatening medical event to shake consumer confidence in Healthcare IT -- and spur more serious action . For the power grid, holding a nation to a ransom in order to turn the lights back on is a really scary scenario.
Page 1 / 2   >   >>
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...