To maintain secure computer systems, in the past the basics have been tasks like keep systems updated, run anti-virus software, use a properly configured firewall,use a filtering proxy for access to the internet.
The advice on basics has been mechanistic in the past - make the machinery protect itself was the ideal and most hoped-for outcome.
The new Basics include the old things and add:
(from Top 10 Tips for Cybersecurity in Health Care)
What's interesting about the new Basics is the additional items all have something in common: People. Each item focuses on how people interact with the systems, what they should expect and look for in terms of benefits, risks and dangers, and the fact the use of computers and computerized machinery must always remember the human elements for mistake, misuse and out-right abuse.
Why Is Cybersecurity So Hard? puts it succinctly, attributing it to three reasons. The first reason is that which is being recognized more broadly now: It's not just a technical problem. Harvard Business Review's The Best Cybersecurity Investment You Can Make Is Better Training documents the problem. The Small Business Administration is gearing up to help in the effort to train small and medium sized businesses and the AHA is making efforts at training from the top-down and this includes training on and in governance efforts.
It's people that are trying to defeat security, it will come down to people promoting security - as the new Best Practices warrant.
The advice on basics has been mechanistic in the past - make the machinery protect itself was the ideal and most hoped-for outcome.
The new Basics include the old things and add:
- Establish a Security Culture
- Maintain Good Computer Habits
- Plan for the Unexpected
- Control Access to Protected Health Information
(from Top 10 Tips for Cybersecurity in Health Care)
What's interesting about the new Basics is the additional items all have something in common: People. Each item focuses on how people interact with the systems, what they should expect and look for in terms of benefits, risks and dangers, and the fact the use of computers and computerized machinery must always remember the human elements for mistake, misuse and out-right abuse.
Why Is Cybersecurity So Hard? puts it succinctly, attributing it to three reasons. The first reason is that which is being recognized more broadly now: It's not just a technical problem. Harvard Business Review's The Best Cybersecurity Investment You Can Make Is Better Training documents the problem. The Small Business Administration is gearing up to help in the effort to train small and medium sized businesses and the AHA is making efforts at training from the top-down and this includes training on and in governance efforts.
It's people that are trying to defeat security, it will come down to people promoting security - as the new Best Practices warrant.
Comments