BreachExchange mailing list archives

Data Breach Response Best Practices Guide Released by DOJ


From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Mon, 4 May 2015 18:29:58 -0600

http://healthitsecurity.com/2015/05/04/data-breach-response-best-practices-guide-released-by-doj/

The Department of Justice’s (DOJ) Cybersecurity Unit recently released a
data breach response guide to help facilities better prepare for data
security incidents before they occur, as well as what to do after the fact.

While the guide was created with smaller practices in mind, the DOJ stated
that larger organizations that have more experience in cybersecurity
matters can still benefit from the best practices guidance.

“It reflects lessons learned by federal prosecutors while handling cyber
investigations and prosecutions, including information about how cyber
criminals’ tactics and tradecraft can thwart recovery,” the DOJ statement
read. “It also incorporates input from private sector companies that have
managed cyber incidents.”

The guide is divided into three main sections, each of which includes
subsections providing further detail on the best approach to data breach
response and preparation. The three main sections are:

Steps to Take Before a Cyber Intrusion or Attack Occurs
Responding to a Computer Intrusion: Executing Your Incident Response Plan
What Not to Do Following a Cyber Incident

While the guidance does not specifically mention healthcare organizations,
the three sections describe similar approaches that many healthcare
facilities are already putting into place.

For example, when it comes to preparing an incident response plan, the DOJ
said that The National Institute of Standards and Technology’s (NIST)
Cybersecurity Framework provides excellent guidance and should be
considered. This framework is often suggested to healthcare organizations,
as a strong approach to creating a comprehensive and secure cybersecurity
plan.

Additionally, the DOJ guide states that it is important for organizations
to realize that they will likely need to take a different approach to
cybersecurity. Each facility is different, but all entities must assess
their most critical security needs. The DOJ calls these the “crown jewels,”
and said that “before formulating a cyber incident response plan, an
organization should first determine which of their data, assets, and
services warrants the most protection.”

In healthcare, this could be compared to how covered entities must identify
the location(s) of their electronic protected health information (ePHI),
ensuring that the sensitive data is identified so it can be properly
secured.

Assistant Attorney General Leslie R. Caldwell broke down the finer points
of the best practices guide at a DOJ Criminal Division Cybersecurity
Roundtable discussion last week:

“This guidance is built on our experience prosecuting and investigating
cybercrime, and incorporates knowledge and input from private sector
entities that have managed cyber incidents.  It is a living document, which
we will continue to update as the challenges and solutions change over
time.  It is an example of the type of assistance that we plan to continue
to provide to elevate cybersecurity efforts and to build better channels of
communication with law enforcement.”

Caldwell added that the DOJ will prepare further legal guidance “on other
subjects that may be helpful to potential victims of cybercrime,” and that
the department has already been working with the private sector to,
including computer security researchers, industry groups and trade
associations, and financial institutions.

“Put simply, at the Criminal Division we see ourselves as engaged in a
long-term battle against cybercrime – a battle that we will only meet with
success if we collaborate with all of you as we surmount obstacles and
design innovative solutions,” Caldwell said.
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss
For inquiries regarding use or licensing of data, e-mail
        sales () riskbasedsecurity com 

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus 
on the right security.  If you need security help or want to provide real risk reduction for your clients contact us!

Current thread: