Compliance often drives data security, but is it enough? In today’s rapidly evolving cyberthreat landscape, regulatory compliance provides a foundation for strong security, but simply meeting compliance standards is no longer sufficient. Meeting compliance standards is essential to remaining on the right side of the law, but the controls only provide a minimum framework for the protection you need. Consider that compliance is only part of the outcome of an effective security program.
Government agencies, non-profit groups, and special industry associations direct compliance standards, and create a blueprint for the protection of sensitive data. Enforcement and accountability occurs through audits and assessments that are either self-directed or conducted by a third party—where the end goal is to pass the compliance audit. Although seemingly similar, security is the sum of all the processes, policies, and tools that safeguard your data; it’s measured by risk mitigation and your ability to respond to threats. Compliance is necessary for organizations in regulated industries, while effective security is valuable to all organizations.
If you manage sensitive data, including electronic protected health information (ePHI) or financial information, you must adhere to regulatory compliance. In healthcare, the Health Insurance Portability and Accountability Act (HIPAA) outlines regulations for protecting ePHI. The Payment Card Industry Data Security Standard, the Dodd-Frank Act, and the Sarbanes-Oxley Act provide guidelines for the financial industry, including financial technology companies.
Unfortunately, many businesses trust these regulations to provide adequate data security. In reality, compliance frameworks are not prescriptive—and must be adapted to meet your unique business needs, since no two environments are the same. Organizations like the U.S. Department of Health and Human Services and PCI Security Standards Council, who manage regulation content, only publish updates intermittently. Since threats are continuously changing, you need to build on your compliance efforts with frequent security updates—processes, technology, and risk management activities should be regularly tested and improved. Unlike compliance, where you follow rules and check off to-do’s, security requires an ongoing strategy that’s never fully “complete.”
With cybercrime costs projected to rise to an estimated $2 trillion this year, you can’t afford to place blind trust in regulatory guidelines. If you want to educate yourself on the latest security best practices, we recommend these trusted sources: The International Standards Organization (ISO), National Institute of Standards and Technology (NIST), World Wide Web Consortium (W3C) and the Cloud Standards Consumer Council.
“Moving from a compliance mindset to one focused on managing and mitigating risk can be difficult, but is important and necessary in this dynamic and often dangerous world,” says SVP and CIO Christian Anschuetz for CIO.com.
Every year, security-conscious organizations must revisit their security management operations. Continual optimization is the key to risk management. Keep these data security best practices in mind as you improve your policies and procedures:
It’s not enough to simply develop these security control policies; you must also monitor and continuously evaluate them against all possible risks. Plan frequent reevaluations of asset values and analyze the risk landscape to be sure your security efforts remain relevant and adequate. Be aware that despite your best efforts, incidents can happen. Your ability to detect, respond, and manage incidents makes all the difference.
As you move more of your workloads to the cloud, also consider that you’ll need different dataprotection, as cloud security requires layers of logical security. Encryption, key management, user access control, and multi-factor authentication improve security for data that’s transferred in and out of the cloud. Although it seems obvious, not everyone has been able to wrap their mind around security in the cloud. When the use of encrypted storage on portable devices and laptops increased in 2017, the healthcare industry experienced a reduction in the exposure of ePHI, compared to previous years, according to the HIPAA Journal.
2017 was a rough year for many organizations, with security breaches affecting everyone from Equifax to the NSA in the Wannacry data leak. Learn from their mistakes, and plan to expand your IT strategy to include best practices for data security and risk management this year.
Additional Resources on This Topic:
The Big Disconnect: 2017 Data Threat Landscape
Top 6 Breach Response Best Practices for 2017
A Snapshot of the 2017 SecurityMetrics Guide to HIPAA Compliance: The Status of Healthcare Security
This article was first published on OnRamp.
In this guest contribution from Steve Vonder Haar, Senior Analyst with Wainhouse, a Futurum Group…
In this guest contribution from Craig Durr, Senior Analyst with Wainhouse, a Futurum Group Company,…
Futurum's Daniel Newman dives into the recent announcement coming out of Micron, that they will…
Futurum analyst Michael Diamond recaps the Amazon Devices and Services event and reviews some of…
Futurum senior analyst Steven Dickens provides his take on the latest announcements coming out of…
Futurum’s Ron Westfall and Daniel Newman examine Micron’s financial results for the fourth quarter 2022…