BreachExchange mailing list archives
Data Breach Response Best Practices Guide Released by DOJ
From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Mon, 4 May 2015 18:29:58 -0600
http://healthitsecurity.com/2015/05/04/data-breach-response-best-practices-guide-released-by-doj/ The Department of Justice’s (DOJ) Cybersecurity Unit recently released a data breach response guide to help facilities better prepare for data security incidents before they occur, as well as what to do after the fact. While the guide was created with smaller practices in mind, the DOJ stated that larger organizations that have more experience in cybersecurity matters can still benefit from the best practices guidance. “It reflects lessons learned by federal prosecutors while handling cyber investigations and prosecutions, including information about how cyber criminals’ tactics and tradecraft can thwart recovery,” the DOJ statement read. “It also incorporates input from private sector companies that have managed cyber incidents.” The guide is divided into three main sections, each of which includes subsections providing further detail on the best approach to data breach response and preparation. The three main sections are: Steps to Take Before a Cyber Intrusion or Attack Occurs Responding to a Computer Intrusion: Executing Your Incident Response Plan What Not to Do Following a Cyber Incident While the guidance does not specifically mention healthcare organizations, the three sections describe similar approaches that many healthcare facilities are already putting into place. For example, when it comes to preparing an incident response plan, the DOJ said that The National Institute of Standards and Technology’s (NIST) Cybersecurity Framework provides excellent guidance and should be considered. This framework is often suggested to healthcare organizations, as a strong approach to creating a comprehensive and secure cybersecurity plan. Additionally, the DOJ guide states that it is important for organizations to realize that they will likely need to take a different approach to cybersecurity. Each facility is different, but all entities must assess their most critical security needs. The DOJ calls these the “crown jewels,” and said that “before formulating a cyber incident response plan, an organization should first determine which of their data, assets, and services warrants the most protection.” In healthcare, this could be compared to how covered entities must identify the location(s) of their electronic protected health information (ePHI), ensuring that the sensitive data is identified so it can be properly secured. Assistant Attorney General Leslie R. Caldwell broke down the finer points of the best practices guide at a DOJ Criminal Division Cybersecurity Roundtable discussion last week: “This guidance is built on our experience prosecuting and investigating cybercrime, and incorporates knowledge and input from private sector entities that have managed cyber incidents. It is a living document, which we will continue to update as the challenges and solutions change over time. It is an example of the type of assistance that we plan to continue to provide to elevate cybersecurity efforts and to build better channels of communication with law enforcement.” Caldwell added that the DOJ will prepare further legal guidance “on other subjects that may be helpful to potential victims of cybercrime,” and that the department has already been working with the private sector to, including computer security researchers, industry groups and trade associations, and financial institutions. “Put simply, at the Criminal Division we see ourselves as engaged in a long-term battle against cybercrime – a battle that we will only meet with success if we collaborate with all of you as we surmount obstacles and design innovative solutions,” Caldwell said.
_______________________________________________ Dataloss Mailing List (dataloss () datalossdb org) Archived at http://seclists.org/dataloss/ Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss For inquiries regarding use or licensing of data, e-mail sales () riskbasedsecurity com Supporters: Risk Based Security (http://www.riskbasedsecurity.com/) YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus on the right security. If you need security help or want to provide real risk reduction for your clients contact us!
Current thread:
- Data Breach Response Best Practices Guide Released by DOJ Audrey McNeil (May 12)
