Category Archives: Internet Security

Save 20 Percent on AVG Internet Security Unlimited, AVG Ultimate – PCMag

When it comes time to invest in an internet security suite, it only makes sense to protect everything.

Most homes aren't limited to a single internet-connected device anymore. The whole family is spread over laptops, tablets, and smartphones, and all of them are potentially at risk for the worst kinds of malware. So when it comes time to invest in an internet security suite, it only makes sense to protect everything. And now for a limited time, you can pick up AVG Internet Security Unlimited or AVG Ultimate for 20 percent off.

Get this deal

First, let's look at AVG Internet Security Unlimited. Normally priced at $69.99 per year, today's discount will drop that down to just $55.99. Not only does it protect against the likes of trojans and spyware, but it also blocks phishing links, filters spam, delivers real-time security updates, re-enforces your security with an enhanced firewall, and encrypts your most important data.

If you're looking for some performance benefits as well, consider opting for AVG Ultimate instead. You'll receive the same protections as the Unlimited suite above, but it's also capable of performing automatic routine maintenance, de-cluttering your drive, updating your apps, improving your battery life, and stamping out duplicate files. And despite typically costing $99.99 annually, you'll only end up paying $79.99 per year with today's deal.

The best part? Both Unlimited and Ultimate come with a 30-day money-back guarantee. Try out this service, install it on your devices, and see if it's a good fit for you. If you're not happy with this suite, AVG will issue a refund.

Note: Terms and conditions apply. See the AVG site for more information.

For more great deals, go to TechBargains.com.

Our commerce group sources the best deals and products for the PCMag Deals posts. We operate independently of Editorial and Advertising and may earn a percentage of the sale, if you buy something via a link on the post. If you are interested in promoting your deals, please contact us at commerce@ziffdavis.com.

Go here to see the original:
Save 20 Percent on AVG Internet Security Unlimited, AVG Ultimate - PCMag

Bitdefender Internet Security 2017 One of the most efficient security suites – GameSinners (press release) (blog)

Bitdefender is one of the most popular anti- virus and anti- malware solutions out there. It has been around for a while now, and thankfully, it seems that it only got better over time. All products of the company are extremely efficient when it comes to protecting your home computer, your office computer or other devices. Bitdefender Internet Security 2017 is one of the most efficient security suites one can install on their computer at this point. It offers a great number of useful features, yet it is simple to use. You really dont have to be an IT specialist to make use of this software.

First of all, Bitdefender Internet Security 2017 is easy to install and has a clean users interface. Users wont need to go through tens or hundreds of tabs until they find what they are looking for. Everything is overseeable in this program and even a novice can easily learn how to get around the software. Users will find a series of tabs that will redirect them towards the different security components offered by the program. The security suite works great on Windows systems, Mac computers, iOS and Android devices too. However, Windows users reported a better user experience than Mac users did. Even so, the program is suitable for devices running on either of these operating systems.

As if the previous versions of Bitdefender werent great enough, Bitdefender Internet Security 2017 brings even more to the table. The latest edition of the software offers a high- grade protection against internet threats, advanced protection against ransomware attacks, a two-way firewall, and an efficient Parental Advisor. Also, the program now features an improved password manager and a File Shredder. One of the best features of the Bitdefender Internet Security 2017 is its Autopilot mode. Users wont get any annoying popups and alerts. The security suite silently works in the background, making sure that the system is protected against all the threats.

The Bitdefender Internet Security 2017 is not only easy to use, it is also extremely efficient. The security suite performs really well in tests. The software offers 100% protection againstestablished malware and zero-day threats according to AV-TEST.org. Basically, this is the ultimate level of protection one can expect from an antivirusor an anti- malware solution. The security suite almost instantly blocks ransomware attacks too. This way, all the important and sensitive data is protected all the time.

Users can also enjoy the benefits of theweb-based remote management console that now looks even better. As its name suggests, thanks to this feature, users will remotely gain access to information regarding their registered computers status and they can enable or disable Autopilot mode too. While the password manager normally performs extremely well, it seems to struggle a little bit when it comes tonon-standard password pages. To be more exact, on this kind of pages the password manager sometimes fails to fill all fields in some web forms. Other than this, the password manager is very efficient, just like its browser extension.

We already mentioned the Parental Advisor featured by Bitdefender Internet Security 2017. This feature allows users to set up a different account for each child. After setting up the accounts and linking them to the specific devices, parents can get reports on the programs and apps they use. if any of them seem to be insecure, parents can simply click on them and thus prevent the child from using them again. On Android devices, parents can also block certain contacts. This way they will be unable to contact the child again. And vice-versa. To take things even further, through this feature parents can even mark certain areas as secure or insecure. The Bitdefender Internet Security 2017 will automatically let them know whenever their children enter restricted areas.

Overall, the Bitdefender Internet Security 2017 performs really well. It efficiently protects every device it is installed on, with a high grade of success in detecting and blocking threats. Some would think that this means the program will seriously slow their system down when working. Thankfully, it isnt the case with the Bitdefender Internet Security 2017. While it will have an impact on your devices performance, it wont be a notable one.

Bitdefender Internet Security 2017 is now on sale. Users can save $35 is they choose to install the security suite on three devices. In this case, they will need to pay $44.99 for a one- year subscription. This is even lower than the price they would pay for installing the suite on only one device, which would cost them $59.99. Of course, customers can install the security suite on up to 10 devices for $89.99. They can also buy two- years of three- years subscriptions.

Originally posted here:
Bitdefender Internet Security 2017 One of the most efficient security suites - GameSinners (press release) (blog)

The Whole Internet Is Managed By 14 People; Each One Is A Security Keyholder – Fossbytes

Short Bytes:There are 14 people who handle the Internet. These people are the members of ICANN. This organizationchecks Internet security, as well as links domains to IP addresses. There are seven people who hold the key, and the other seven are backup keyholders. The security of the organization is very tight considering its responsibility as an Internet security system.

A team of 14 people has control on the Internet. Each of the individual holds a key, which whencombined together forms the main master key of the whole of the Internet networks worldwide. Seven of these fourteen people are the main keyholders, while other seven are the backup keyholders.

The information was gathered by The Guardian. And all the details were based on the highly secure Key Ceremony attended by its special project editor James Ball.

The team joins in a meeting held four times a year. As reported, all the keyholders of the unit are highly experienced and personalized in Internet security. Further, no country has too many keyholders or rather its not really allowed.

The body handles the Domain Name System that links web address to IP address. For every web page, there is a numerical internet address. The objective of the master key concept is to secure the whole Domain Name System.

There are multiple security levels. Each keyholder keeps their metal keys in the most security-tightened place. All these safety and security is taken care by an organization named Internet Corporation for Assigned Names and Numbers (ICANN) which holds the system.

For that matter, if we talk about the security system of the office, its not easy to get inside their working arena, quite obvious. It actually requires passwords to pin entry to the smart card to biometric hand scan to enter any room. That too only one door at a time can be opened. It is like a mantrap, says James from The Guardian.

But did you notice their strategy, plan or security? Well, ICANNs plan is a backup for situations of cyber attacks. The reason the keys are divided among 14 is only to ensure no power goes to a single hand, which is otherwise risky.

Go here to see the original:
The Whole Internet Is Managed By 14 People; Each One Is A Security Keyholder - Fossbytes

In our opinion: Individuals and governments should do more to recognize and combat cyber attacks – Deseret News

DepositPhotos

"Its important that businesses, governments and individuals adopt and continually revise best practices as a way to both deter and deny malicious internet actors from profiting off of cyber vulnerabilities. Those who would never think to keep their door unlocked or ajar in a rough neighborhood don't think twice about letting malicious hackers gain access to their private data."

Individuals and governments should do more to recognize and combat insidious cyber attacks. Sen. Orrin Hatchs new bipartisan bill, the so-called Promoting Good Cyber Hygiene Act, is a fine first step worthy of congressional support.

Only a few weeks after the so-called WannaCry ransomware attack paralyzed tens of thousands of computers, yet another internet outbreak hit Ukraine and 64 other countries this week, including the United States.

In Kiev, the capital of Ukraine, ATMs stopped working, according to the New York Times. About 80 miles away, workers were forced to manually monitor radiation at the old Chernobyl nuclear plant when their computers failed. Well-known businesses were affected such as the U.S. pharmaceutical company Merck and the chocolatiers at Cadbury.

A separate attack occurred late last month targeting members of the British parliament. Utah, which is home to one of the United States intelligence communitys largest data storage centers, is undoubtedly an international target.

According to figures from the Department of Justice, since 2016 there have been an average of 4,000 ransomware attacks a day thats a 300 percent year-to-year jump from 2015.

Many of these kinds of attacks are preventable if individuals and corporations follow what Hatch calls good cyber hygiene. His act would direct the National Institute of Standards and Technology to establish Internet security best practices." The information would be continually updated, regularly reviewed and available to the public the standards are voluntary.

Skeptics might say that publicly publishing and producing safety guidelines only helps bad actors better understand how to get around cyber security. Yet, most experts say that many attacks are not particularly sophisticated and can be stopped by taking rudimentary safety precautions.

Some of these precautions include:

These are just some basic steps for guarding against attacks.

Its important that businesses, governments and individuals adopt and continually revise best practices as a way to both deter and deny malicious internet actors from profiting off of cyber vulnerabilities. Those who would never think to keep their door unlocked or ajar in a rough neighborhood don't think twice about letting malicious hackers gain access to their private data.

Sen. Hatch anticipates bipartisan support for his bill, SB1475. This should be a priority for members of Congress. After all, ransomeware knows no partisan boundaries.

See the original post here:
In our opinion: Individuals and governments should do more to recognize and combat cyber attacks - Deseret News

See Which Mac Antivirus Protects Best (and Worst) – Laptop Mag

"Macs don't get malware" was a popular rallying cry around the same time those "I'm a Mac; I'm a PC" commercials were a thing, but it hasn't been true for a while. MacOS is susceptible to everything from Trojans to ransomware, and if you don't get a security suite to protect yourself, you could be the next victim.

The good news is that the vast majority of macOS protection programs offer excellent protection; the bad news is that a well-known program called MacKeeper does not, especially when dealing with run-of-the-mill malware.

This information comes from AV-TEST, a Madgeburg, Germany-based testing lab that periodically evaluates antivirus software across a variety of platforms. In April and May 2017, the company took a look at 10 of the most prominent masOS antivirus products. It discovered that nine of the products were up to snuff; furthermore, four of them had functionally perfect detection rates.

MORE: Best Mac Antivirus Software and Apps

Bitdefender Antivirus for Mac, Intego Mac Internet Security X9, Kaspersky Internet Security for Mac and Symantec Norton Security all successfully detected every piece of malware that AV-TEST threw their way, without producing any false positives or putting undue stress on the system. Except for Intego, all also detected nearly 100 percent of Windows malware that might be lurking on a Mac. If you have one of those four programs, you're all set; if not, consider getting one.

At the other end of the spectrum was the ignominious MacKeeper, which detected only 85.9 percent of incoming threats. This may sound like a B grade, but AV-TEST sets its minimum threshold for recommendation at 90 percent with no false positives. (We'd put the minimum at 95 percent.)

While it's probably better to have MacKeeper than nothing at all, even that is open to debate, as many experts consider MacKeeper to be worse than useless. If you're going to pay money for an AV program, it may as well be one that detects almost every threat.

Trend Micro Antivirus for Mac came in at second place with 99.5 percent of malware detected. Canimaan Software ClamXav Sentry, ESET Endpoint Security and Sophos Central Endpoint tied for third with 98.4 detection rates each. Any of those programs should protect you just fine.

But ProtectWorks AntiVirus scored a 94.6 percent detection rates, which is lower than what we're comfortable with. With antivirus software, what matters is how much slips through, and in that respect, ProtectWorks did three times as badly as ClamXav, ESET or Sophos.

It's worth noting that all of the macOS AV programs tested worked in conjunction with the built-in macOS security protocols, which include the Gatekeeper application screener and the XProtect signature-based malware checker. (This isn't the case with Windows, which requires you to either accept its built-in security suite or install a third-party one.)

Installing a third-party AV program on your Mac will not compromise the protection that already Apple offers. It's to your advantage to install something as long as it's something other than MacKeeper or ProtectWorks.

Image credit: Guteksk7/Shutterstock

See more here:
See Which Mac Antivirus Protects Best (and Worst) - Laptop Mag

APG cable improves Vietnam’s internet security – VietNamNet Bridge

VietNamNet Bridge - Though the APG submarine cable broke twice in six months, Vietnam Internet Associations (VIA) secretary general Vu The Binh said that APG has helped improve security and provisioning capability for Vietnams internet.

The APG project attracted many Asian telecom groups, including Japanese NTT Docomo, Chinese China Telecom and South Korean KT. The four Vietnamese investors include VNPT (the Vietnam Post & Telecommunication Group) , Viettel, FPT Telecom and CMC Telecom.

With a length of 10,400 kilometers, the APG cable is located under the Pacific Ocean, connecting points in nine countries and territories including China, Hong Kong, Taiwan, Korea, Japan, Malaysia, Singapore, Thailand and Vietnam.

The system has a capacity of 54 terabits per second with the Internet speed of 20 times higher than AAG (Asia America Gateway).

AAG also has to be repaired so often. In the first half of 2015 alone, it was in trouble four times, on January 1, April 23, May 26 and early June.

While AAG cable plays an important role in connecting Vietnam and the world, APG is hoped to help the connection become faster and more stable, and help ease reliance on AAG.

Binh told the press in late December 2016 that APG helped improve security for Vietnams internet.

VIAs representative also said though ISPs in Vietnam still have not provided detailed information about capacity through APG, the impact on international internet connectivity was less serious than before.

However, APG twice broke down within a short time. It broke for the first time on December 31, 2016 at positions near Singapore and Chongming, China. The latest breakdown occurred on June 20, 2017 at a position just 125 kilometers from Da Nang City.

According to CMC Telecom, one of the ISPs which develop APG, the trouble caused 100 percent loss of AGP capacity to Vietnam.

When asked if APG would break down regularly like AAG, Binh said he still doesnt have enough information to compare APG with AAG.

However, he believes the APG developers have enough information about AAGs status and operation.

Problems with cables are unpredictable. Therefore, ISPs all have to prepare contingency plans to ensure smooth operation. The plans depend on their business strategies and targeted clients.

VIAs official said internet service in Vietnam is competitive, with the service fee much lower than in other regional countries.

RELATED NEWS

Why does the AAG underwater cable have to be repaired so often?

APG submarine cable broken, Internet connection affected

Buu Dien

Read more here:
APG cable improves Vietnam's internet security - VietNamNet Bridge

Global Internet Security Market to Grow at a CAGR of 8.7%, 2017-2021 with Hewlett Packard, IBM, Intel & Symantec … – Business Wire (press…

DUBLIN--(BUSINESS WIRE)--Research and Markets has announced the addition of the "Global Internet Security Market 2017-2021" report to their offering.

The global internet security market to grow at a CAGR of 8.70% during the period 2017-2021.

This report, Global Internet Security Market 2017-2021, has been prepared based on an in-depth market analysis with inputs from industry experts. The report covers the market landscape and its growth prospects over the coming years. The report also includes a discussion operating in this market.

One trend in the market is convergence of technologies. The need to protect networks from advanced cyber threats has led companies around the world to adopt multiple security solutions such as messaging (SMS/ MMS) security, web security, e-mail security, data loss prevention, endpoint security, and network security solutions.

According to the report, one driver in the market is growing need for secure and compliant cloud solutions. Performing online operations in sectors including medical, retail, and finance, which have strict security standards requires a secure and compliant cloud solution. IoT includes technologies such as radio frequency identification (RFID), barcodes, sensors, and GPS. These technologies are mainly used to monitor and manage the remote physical assets in an organization.

Key vendors:

Other prominent vendors:

Key Topics Covered:

Part 01: Executive summary

Part 02: Scope of the report

Part 03: Research Methodology

Part 04: Introduction

Part 05: Market landscape

Part 06: Five forces analysis

Part 07: Market segmentation by category

Part 08: Market segmentation by end-user

Part 09: Geographical segmentation

Part 10: Decision framework

Part 11: Drivers and challenges

Part 12: Market trends

Part 13: Vendor landscape

Part 14: Key vendor profiles

For more information about this report visit https://www.researchandmarkets.com/research/2pp24q/global_internet

Read more here:
Global Internet Security Market to Grow at a CAGR of 8.7%, 2017-2021 with Hewlett Packard, IBM, Intel & Symantec ... - Business Wire (press...

Immigration Department lax on cyber security and vulnerable to attacks, experts say – ABC Online

Posted June 28, 2017 13:47:37

Cyber security experts fear the Immigration Department is dragging its feet on internet security in the wake of global ransomware attacks and may be vulnerable.

The department has failed to comply with the Australian Signals Directorate's (ASD) top four security measures including patching for years, despite repeatedly promising to do so.

A damning audit earlier this year found the department was vulnerable to external attacks that could compromise sensitive information, including national security data.

But the department's chief information officer, Randal Brugeaud, will not give a deadline for compliance with the intelligence agency's recommendations.

"The failure of key government departments to be compliant with ASD's top four mitigation strategies is alarming," Greg Austin from the Australian Centre for Cyber Security said.

"These are only the most basic measures designed to begin to get organisations on the difficult path of transforming cyber security culture."

Computer security expert Richard Buckland said he was "surprised" by the department's approach.

"They have so much data and they are in such a critical position in our overall strategy that really we would all expect them to get this right," Dr Buckland said.

"They are very good at expecting compliance from everyone else, so I am surprised that compliance mentality does not apply to their internal systems."

A department spokesman told the ABC it was taking the challenge seriously and its information communications technology (ICT) systems had not been breached.

Earlier this month, Mr Brugeaud revealed the department may not be compliant with patching processes recommended by the Prime Minister's cyber security adviser, Alistair MacGibbon.

Patching is a term used to describe updating operating systems and applications to ensure they are protected from malware or ransomware.

Mr Brugeaud told a Senate inquiry that a monthly patching cycle would not be rolled out until next financial year.

"On application patching, which is quite a challenge for all organisations over the next two to three years we will get to a point where we are able to be fully compliant in applications," Mr Brugeaud said.

The department spokesman told the ABC it was now in the second year of a five-year ICT plan that would ensure compliance with the ASD recommendations.

But Dr Buckland said the five-year time frame was "astonishing".

"A five-year plan to deal with this is just the wrong time scale it makes me concerned about how seriously they are treating this," he said.

"In five years everything will have changes. It raises the question, how seriously are they taking cyber security?"

The department's cyber security processes are now the subject of a senate inquiry led by Liberal senator Dean Smith.

Mr MacGibbon told the inquiry compliance with the ASD's recommendations were only one approach to security.

"I have found that there is a prevailing "tick box" compliance culture which is in some respects, perversely driven by a fear of audit failure," Mr MacGibbon said.

"By looking only to these snapshots, we may create a culture of fear and thereby harm our security."

In its submission, Immigration pointed out a merger with the former customs agency in 2015 presented "an enormous challenge" for its ICT department.

"Combined, the two agencies have over 900 applications, of which 569 are unique," the submission said.

"Of the 279 business critical applications, approximately 70 per cent are bespoke."

Topics: hacking, science-and-technology, internet-technology, computers-and-technology, defence-and-national-security, government-and-politics, federal-government, australia

Read this article:
Immigration Department lax on cyber security and vulnerable to attacks, experts say - ABC Online

Internet security awareness – Maryville Daily Forum

Being safe online is important every day. There may be days devoted to internet security awareness, but you need to be careful every time you go online.

Do you know what it takes to be safe online? You probably connect daily to get information, shop, socialize, or work. Every time you go online, you need to avoid the risk of theft or fraud. Here are some tips to use while visiting the Social Security website and the other websites you use.

Use Strong Passwords--Strong passwords have at least eight characters and include capital letters, numbers, and non-letter characters. These passwords make it harder for someone to hack your account.

Dont Recycle Passwords--Although it requires effort to think of new passwords constantly, it provides safety when you do. What if you use the same password for every site and you lose your password? If someone finds it, they could get access to all your accounts. Many people choose to reuse dont be one of them.

Take Advantage of Multifactor Authentication--Many websites offer the option to use a second factoror methodin addition to just a username and password to ensure that only you access your information. Using more than one factor to establish identity makes it harder for someone to get into your account and steal your personal information. Beginning June 10, 2017, Social Security requires multifactor authentication to access a my Social Security account. Customers choose whether to receive a one-time security code to either their phone or email in order to create a new account or sign into their account. Visit this link to find out more about how to secure your personal my Social Security account: http://www.socialsecurity.gov/myaccount/verifyandprotectid.html. Consider using multifactor authentication whenever its offered to protect your information.

Read Scam Alerts--For information about fraudulent activities related to Social Security, you can find information at our blog Social Security Matters under the Newsroom section at blog.socialsecurity.gov. One way to avoid identity theft is to create your own my Social Security account, if you havent already. When you have an account, no one else can set up an account using your information. Social Securitys Office of the Inspector General investigates fraud involving Social Security and they publish Fraud Advisories at oig.ssa.gov/newsroom/news-release. The Federal Trade Commission website publishes information about scams that appear in the news at http://www.consumer.ftc.gov/scam-alerts. Youll want to be aware of current scams to avoid being tricked.

Review Your Online Accounts and Credit Reports--Just as you review your earnings record with Social Security for accuracy at http://www.socialsecurity.gov/myaccount, you should review your bank and credit card accounts for accuracy. Get a free copy of your credit report available annually from the three credit reporting agencies (Experian, Equifax, and Transunion) at http://www.annualcreditreport.com/ and check it for incorrect entries.

Protecting your identity can be daunting. Guarding your personal information requires investing some time, but is worth it. Discourage theft and fraud by adopting these security practices when you use the internet.

Danny Zimmerman is the Social Security District Manager in Maryville, Missouri

View post:
Internet security awareness - Maryville Daily Forum

Health systems tout Security CIS Controls in fight against cybercriminals – Healthcare IT News

In the hectic, sometimes crazed world of healthcare cybersecurity, a little guidance can be a welcome thing for CIOs and CISOs. Thats why the Center for Internet Security pieced together its CIS Controls, a framework of 20 controls with the aim of leading healthcare organizations to better, more locked down systems and data security. And some healthcare organizations are using these controls to great effect.

The CIS Controls framework is very approachable; its organized in a prioritized manner, and even the top-level controls are presented in such a way that as technologists we can communicate them intelligently in a conversation to internal stakeholders who are concerned about risk, said Roger Lutz, interim chief information officer at Butler Health System. And we can discuss things at that level, obfuscating the deeper sub-controls, of which there are many, getting interested stakeholders to understand how we are addressing cybersecurity risk.

[Also:Outsourced cybersecurity staff, one way healthcare is getting around the talent shortage]

Healthcare organizations need to select a cybersecurity framework to work from, otherwise, they will simply be reactionary to the latest threats and whatever is in the news, Lutz said.

While your own judgement may be excellent, you may be missing something, he said. To have that framework and work toward a common set of technology controls of which a great number of very intelligent people have come to unified agreement, it helps us to make a lot of real progress over time and record that progress that shows advancement in information security and keeps us on track.

[Also:Here are the dos and don'ts when hiring healthcare cybersecurity pros]

At 20, the number of controls is small enough to manage easily, and further, its easy for both technology staff and management executives to understand all of the controls, said an auditor at a large health system in Tennessee, who wished to remain anonymous due to the sensitive nature of security issues.

There are other frameworks, such as the NIST framework and the ISO 27002, he said, but the Center for Internet Security CIS Controls are just a lot easier to understand.

Lutz points to control No. 5 as an example: Controlled Use of Administrative Privileges.

We identified the need some time ago to control our administrative credentials among the various staff on the information systems team, he said. We implemented a system that does centralized privileges access control. It creates a vault, our users log into the vault to pull the privileged access credentials for other systems so we can automate long, complex passwords for all of our administrators and so forth. This control was one we nailed down pretty well.

Lutz said it is interesting and helpful the way the Center for Internet Security has constructed the controls, where one measures four different categories for each sub-control of a control. Control No. 5 has nine sub-controls, from using multi-factor authentication to logging accesses to using a dedicated machine for administrative tasks. Each of those sub-controls are then measured by policy defined, control implemented, control automated, and control reported to the business.

This is an area that really allows you to demonstrate maturity in your information security programs, Lutz said. Not only are you buying a product or implementing a technology change that provides information security to an organization, you are defining how you are going to do it through policy so you have consistency and so from a governance standpoint you paid attention to the other things and implemented it properly.

And control reported to the business is an important and valuable measurement, Lutz added.

This is about having a way to demonstrate things up the chain of command, to show them what you are doing in a way that doesnt boggle them with technology but instead shows them a measurement they can understand, which over time is important, he said.

The large health system in Tennessee has seen many positive results after working with the CIS Controls.

From our audit perspective, by determining which controls are more critical, based on the audits we can give real-time feedback, here are our findings, here is what needs to be improved, here is what we are doing well, the auditor said. That gets management attention; the auditor report goes to the board of directors. There is awareness brought to the cybersecurity program both to the technical folks and management. This is a slow process, we are not able to do 20 in a year, we are trying to get through all 20 every three years.

The results of using the CIS Controls at Butler Health System include bringing focus to the IT and security teams, bringing measurement to processes and therefore the ability to reflect progress to interested stakeholders within the organization, and bringing prioritization to security projects all of which has led to information security maturity, Lutz said.

If you think of any good process, theres focus, measurement, accountability and prioritization in the face of limited resources, he said. With unlimited resources you can do everything all at once and its less of a constraint. But with constrained resources, being able to focus over the months and years and demonstrate progress in a prioritized manner is excellent. And its great working with controls predesigned by an organization that has excellent technical engineering resources at their disposal.

Twitter:@SiwickiHealthIT Email the writer: bill.siwicki@himssmedia.com

Like Healthcare IT News on Facebook and LinkedIn

Read the original:
Health systems tout Security CIS Controls in fight against cybercriminals - Healthcare IT News