How the NIST CSF 2.0 Can Help Healthcare Sector Firms episode artwork

EPISODE · Apr 1, 2024

How the NIST CSF 2.0 Can Help Healthcare Sector Firms

from Info Risk Today Podcast · host InfoRiskToday.com

The National Institute of Standards and Technology's updated Cybersecurity Framework 2.0 can help healthcare organizations better formalize their governance functions to enhance their cybersecurity posture and resilience, said Robert Booker, chief strategy officer at HITRUST.

Episode metadata supplied by the publisher feed · Published Apr 1, 2024

Embed this episode

NOW PLAYING

How the NIST CSF 2.0 Can Help Healthcare Sector Firms

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Colby, Executive Editor at Information Security Media Group. Today, I'm speaking with Robert Booker, who is Chief Strategy Officer at High Trust. High Trust, formerly called the Health Information Trust Alliance, is best known for its common security framework for health and financial information. We're going to be discussing the National Institute of Standards and Technologies' recent update to its cybersecurity framework and what this means for the healthcare sector.

So, Robert, what is the most important things that the healthcare sector needs to know about the NIST CSF 2.0? What are the updates that were made that could most impact how healthcare sector entities consider implementing the NIST framework? It's so timely that we're having this conversation, Mary Ann, thank you so much. So, you know, I think healthcare companies have traditionally been so laser focused on HIPAA and at least in the security perspective, HIPAA security rule, that they oftentimes look at frameworks like the NIST cyber security framework and other things to sort of insular or part of what they need to be considering, you know, just get really super focused on that security rule, implement that security rule and all will be well, certainly from a compliance perspective.

And I think what NIST has done and continues to do is to understand from an organizational and from a practical perspective how organizations look at their cyber security programs. I think the industry has advocated for changes such as what NIST CSF 2.0 provide for quite some time. To your questions, particularly with healthcare, you know, everything about the HIPAA security role is predicated on the concept of risk management and, you know, it's very well Mary Ann, but for the audience, you know, the fact that we don't just have a scorecard of things we must do from a security implementation point of view for healthcare. Organizations are not just encouraged but required to look at a risk analysis and to consider, you know, the inherent risk of their systems to select controls and safeguards in accordance with those risks that do fall into that HIPAA taxonomy that we're talking about.

And lastly, to govern themselves with regard to the execution and completion of those controls. So what we've always had is we've always had the sort of senses we worked with the healthcare and public health sector at the implementation guide level to say, you know, there is this risk selection and tailoring aspect that existed in NIST from the very beginning and putting away to surface that for healthcare companies. And what NIST CSF 2 has done for us now is it's actually formalized that governance function, which I think is quite key. I almost think of it as like an NFL football game is every week your team sets down, they look at film of the opponent and they put together a very specific game plan that is tailored or targeted at winning in that week's contest.

And then they go to the game and they play the game and they find out at the day of whether they've been successful. I think it's a little bit like that in the sense that security isn't the same for the first competitor you're playing against or the second or the third, although there's much commonality. You know, we think of having that ability to do a risk assessment to manage your risk, to look at things like third party risk or supply chain risk management. You know, those are the things I think that continue to create challenges for healthcare entities as they start and continue on their security journey.

And so we really like this aspect of saying let's just formalize governance now, let's see that externalized a bit more. But it also keeps all the things that we really believe are highly valuable, like like tailoring of controls based up on informative references, things like we can do and others can do to say here from a healthcare perspective is how you implement the controls in a prescriptive way so that you know they're right. So I would say, you know, we've added that governance function, which really gives us an organizational wrapper around it, prepares us for that each game we're playing each week. It allows us to be tailored and relevant to the facts that we're facing right now and ultimately allows us to govern it.

So then probably that third party risk piece or the supply chain risk, which I think is so huge in healthcare, because healthcare isn't delivered by one entity, it's delivered by hundreds of entities all working together. And I think we really do need to respect that distinction in how healthcare is delivered in our nation. So Robert, you mentioned HIPAA and as we all know, regulators have been long recommending that healthcare sector entities implement the NIST CSF. In fact, the Department of Health and Human Services and NISTs had previously released guidance to help pepper covered entities and business associates map the HIPAA security rule to the NIST CSF.

How does the NIST CSF 2.0 potentially change that mapping? Yeah, I think what it does is it provides a broader framework, Marianne, a framework that that I would say it extends the mapping from both the front and the back of a security lifecycle. So if you get if you think about HIPAA, you think about that sort of risk analysis to control selection of implementation. I think what we see now with with NIST CSF is we've actually formalized that risk management strategy piece at the front end.

We've formalized policy and organizational oversight, and oversight in my mind runs all the way to the back end of the security lifecycle. So things like ensuring that you are testing and validating and providing strong assurances for your security program really are that oversight dimension at the end. So I think if HIPAA is kind of the center of what you do to select and do security, I think what NIST CSF now gives you is more of an organizational context around all that, which I think is highly valuable because in our experience, we've seen many insurance reports over the years, not just ours, but others. You really have to go back to transparency and integrity of the report.

Like how do we actually know that the controls have been validated and that the controls are operating with effectiveness? And I think NIST provides an approach to that. I would say on the counterpoint of that, there is still this very strong organizational bias towards compliance, which is a very good thing. We definitely want to see organizations be compliant.

And I still think when you look at HIPAA specifically, and even if you look at HIPAA plus NIST CSF 2.0, there's a strong temptation to look at this as a compliance exercise. I know I need to be compliant with the security rule. There is a way now to use recognized security practices which would include NIST CSF as an illustration of providing a common approach to security, which may give me some defensibility from a regulatory perspective. And while I admire and respect all of that, I think we truly appreciate the motivations that creates for the industry, we ultimately still come down to the fact that chasing compliance is not going to be successful alone.

So what we really need to do to take all of this framework and government capability that's valuable for companies in healthcare, what we have to do with that is we have to create the ability to really govern that from an organizational perspective, provide assurances around that. And we need to continue to ask our government partners to make it clearer that we're focused on cyber resiliency and not focused purely on compliance. And I think that's the that's the other really important point here, that NIST has made this pivot in the last probably 18 months or so to change the narrative from let's be compliant or let's focus on your cyber security program more as an execution to focusing on the culture, the company is being centered on cyber resiliency. And when you take when you take what NIST is doing in the context of the national cybersecurity strategy, which the administration released about a year ago now, you know, those things are both good, but only if they're executed in the context of governance and assurance.

And that's really that's that's kind of, you know, it's well, Mary, and it's been our message for so long. It's like, it's great to have the guidance, it's great to have the governance capabilities available, but we simply must know that we're executing and we're executing with distinction. And that's that's what this is all about. I think these tools just provide us additional, you know, arrows and quiver if I could mix my metaphors to allow us to target this problem in a more effective way.

So Robert, how does the NIST CSF 2.0 compare with high trust CSF and the high trust approach? Yeah, I think, you know, high trust named our framework, our CSF goodness, about 15 years ago now. So now we have two frameworks and we continually know that creates some confusion for people, but you know, high trust is a framework of control specifications and implementation guidelines that can be selected, applied and tested. And they're very complimentary to what NIST CSF is.

And we do believe NIST CSF is the cybersecurity framework now, what we provide is this control framework. They're both called frameworks. But I think of them as very complimentary. I think if you want to look at, you know, these macro functions that, you know, NIST CSF now provides six of them in 2.0, govern, identify, protect, detect, respond and recover, you know, those and then the categories and stuff categories underneath those are very valuable, those functions.

But there's a whole lot of work underneath all of that that is necessary to know your risk, select the actual controls and specifications of controls that need to be implemented under that framework, and then test and validate that that's actually operating at a level of effectiveness. And so we kind of think of this as, you know, this is probably the roadmap, but then the cars on the road that you want to put on the road in the right way, or maybe the train, the train on the tracks with train cars in the right order, that's us. You know, we provide, we provide those capabilities and specification. And we're certainly not the only one, you know, there are things like NIST 800, you know, 173 out there that have similar constructions.

But we believe what's really valuable in the approach we take as ours is tailored and based upon risk and does have a level of health care experience in the context worth that, you know, many organizations find valuable. And so we do see them as very complimentary. I do think at the end of the day, you know, what Hydros wants to recognize the fact that, you know, the frameworks themselves, while very important, don't do the job. The job requires risk assessment, control selection, implementation, and then testing validation assurance.

And it's only if you run to the very end and you know how your organization is continually examining their control framework and asking themselves like, is something new going to be needed? Is something else going to be required? Are there new threats? Are there new attacks or new vulnerabilities?

All of those things that I think are just the hard work of very motivated people every day trying to stay ahead on this problem. It's really those things together being applied, you know, almost in anger, if you will, to the industry problem that are valuable. And so we just think, ultimately, if I care about health care security and I do passionately as a former health care professional, we need frameworks and guidance that are actually practical, they're implementable, they are testable, they have assurances that we can rely upon, all those things are quite important. And so we think those two things together work for us.

And very briefly, Robert, I understand that Hydros also issued a companion document for the NIST CSF 2.0. What do the health care entities out there need to know about this and how they would use this companion document? It's really an extension of the guidance documents that we've been working on in concert with the cyber security working group at the industry level for that goes back five, six years since we began that work. So we've been constantly amending and supporting as a member of the working group this continued progress on how to implement NIST CSF, the first version in the context of health care.

So how does organization look at risk? How does a health care entity select controls based upon their risk? How are those controls implemented and executed? So that sort of how to guide what we've done with 2.0 is we've just updated the guidance to make sure it reflects the full breadth of the new control of functions within NIST CSF.

So the first part is just it's just an important relevant update. But I actually think we actually thought a lot about making it broader than health care and focus. So there was always this sort of inherent perhaps understanding, I'm not calling it, misunderstanding that because Hydros works so closely with health and we implemented the sector implementation guide in the past that it was a so health care specific, it wasn't really valuable for other companies. And frankly industries that support health care heavily like technology companies and such.

So there was always this sort of like that's a health care thing and it's very health care focus which which while true was not really designed to constrain itself to health care. What we've done with the new companion document is we've actually focused number one on cyber resiliency which I think is really the goal at the end of the day. So being really clear in terms of positioning the document so that leaders in the industry can explain it to their executive management boards and others to say here's an approach to cyber resiliency that's valuable but also valuable not just for health care but other industries as well especially those companies that are working around health care but even those that do not. And there's a lot of motivation right now in our country to focus on critical infrastructure protection.

You see things happening with energy and nuclear, you see things certainly happening with oil and gas distribution. There's a whole goal in harmonization in the US government right now, regulatory harmonization. We actually would advocate that things like the approach we've implemented which is entirely centered on government standards with the assurances as an important add-on those are valuable for all harmonization efforts. So we're certainly doing our part to try to communicate and educate our government partners on the fact that when you talk about harmonization you have to talk about harmonization in terms of how it's practically going to be implemented.

And so we hope the companion document not only provides education and explanation for the industry but also kind of a how-to guide how do you how do you implement the cyber security framework 2.0 using the high trust approach which is based upon our control framework and the way that we think about assurance and validation. Thank you very much Robert. I've been speaking to Robert Booker of High Trust. I'm Mary Ann Cobissette McGee of Information Security Media Group.

Thanks for joining us.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 1, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!