HIPAA

Respond to the following in a minimum of 175

Due Day 3

As you have been studying this week, controls are measures implemented to reduce the likelihood, as well as impact elements, of risk. Controls may target specific vulnerabilities in an asset or be used to generally protect several assets. Within the healthcare industry, the Health Insurance Portability and Accountability Act (HIPAA) Security Rule helps to target security control selection. The NIST SP 800-53a security control catalog is often used to select and implement security controls to meet the HIPAA Security Rule requirement.

Respond to the following in a minimum of 175 words:

Review the February 2013 Executive Order 13636, “Improving Critical Infrastructure Cybersecurity.”
Consider why NISTSP 800-53a is often used for complying with the HIPAA Security Rule in health care institutions that are private entities.
Given what you have seen as the role of a CISO, how could you succinctly explain the importance of NIST to the System Owner?

Respond to the following in a minimum of 50 words: POE

Hello Class, per this week’s class discussion post, I will be talking
about the February 2013 Executive Order 13636. The executive order 13636
that was signed in February 2013 by former president of the United
States of America Barack Obama has stated that we need to improve the
cyber security aspects that’s associated with the critical
infrastructure that’s in the country. The whole purpose of this
executive order was to improve and increase the core capabilities of our
critical infrastructure to deal with risks associated with cyber
security. The purpose of this order was to adopt cyber security
practices, ensuring data privacy, and secured information sharing
between entities. Also, this order tasks the National Institute of
Standards and Technology to work in close conjunction with the companies
of the private sector to identify the best cyber security practices
within the industry and to build a robust cyber security framework using
them. Next, talking about the NIST SP 800-53A, it is basically an
official catalog published by the NIST as part of the executive order
13636 which tries to implement the kind of security controls that all of
the federal information systems need to implement in order to ensure
the information security as well as data privacy to the users whose data
that they collect and store and other types of critical information
that has to do with their business operations. Also, it plays an
important role in the HIPAA act that specifically states how healthcare
organizations are supposed to collect, store, and process the patients
data so that it can’t be misused by hackers or people with malicious
intent and to prevent data theft. The NIST 800-53A specifies the kind of
security controls and the information security and data privacy
framework that a health insurance company needs to implement in order to
ensure the safety and security of the patient’s data (information). As
the Chief Information Security Officer (CISO), working in the
organization, it my responsibility to make the key-decision makers
within the organization about the importance of information security and
data privacy as well as the stance of the federal government over the
same.

Respond to the following in a minimum of 50 words: Brooker

There are a high number of frauds and data breaches increasing at a
faster pace due to the increment within the cyber capabilities of the
cyber hackers. I would prepare the presentations and cite important
details associated with the cyber security framework and security
controls that must be present within a private organization in order to
ensure information security. Also, I would include the positives
(advantages) of adopting such types of practices and their positive
effects on the business and growth of the organization. One advantage is
to make sure that private organizations make sure that the user
information in a safe and secure manner against any types of threats so
that users don’t lose money or that their sensitive (private)
information is not compromised. Also, another advantage is to improve
the image and reputation of the organization and that people are
confident that their personal information is being trusted with and
handled well with. Finally, another advantage is that this would
increase the competition amongst other similar organizations in terms of
the information security framework. Also, this would help other similar
organizations help upgrade their security IT Infrastructure Framework
as well.

Last Completed Projects

topic title academic level Writer delivered