Skip to main content

What Keeps Me Up at Night 2012

I've written several posts about the issues that keep me up at night.  Here's what I wrote in 2011.

Today, my team presented a list of risks to the Compliance, Audit and Risk Committee at BIDMC.   Here's my list of top risks for 2012:

1.  Old Internet browsers - many vended clinical applications require specific versions of older browsers such as Internet Explorer 6, which are known to have security flaws.  We've worked diligently to eliminate, upgrade or replace applications with browser specificity.   At this point we are 96% Internet Explorer 8/Firefox 7/Safari 5 minimizing our risks to the extent possible.

2.  Local Administrative rights - Of our 18,000 devices on the network, a few thousand are devices that require the user to have local administrative rights to run their niche applications (often the research community doing cutting edge research with open source or self developed software).   We have done everything possible to eliminate Local Administrative rights on our managed devices.

3.  Outbound transmissions - Security has historically focused on blocking evil actors from the internet.   Given the current challenges of malware and infections brought in from the outside, it's equally critical to block unexpected outbound activity.

4.  Public facing websites -  any machine that touches the internet has the potential to be targeted for attack.  We've implemented proxy servers/web application firewalls on most public websites.

5.  Identity and Access management - Managing the ever changing roles and rights of individuals in a large complex organization with many partners/affiliates is challenging.  If an affiliate asks for access to an application, how do you automatically deactivate accounts when users leave an affiliate, given the lack of direct employment relationships?

6.  Anti-virus - the best anti-virus applications only catch about 50% of malware.  Thus, a multi-layered defense is required.  However, adding all those layers impacts performance and can result in false positives.   Balancing security, reliability, and performance is challenging.

7.  Security awareness - When that phishing email arrives asking users for their username/password, social security number, and a DNA sample, some people still fall for it.   Many users surf sites that are known virus distribution sites.   Even social networking is a vector for malware.

8.  Keystroke loggers and screen scrapers - mobile devices and home computers beyond IT control may contain keystroke loggers that capture user credentials, bypassing encryption, VPNs, and other layers of security.

9.  Forensics -  increasingly sophisticated security infrastructure implies more events to research which requires additional staff that are challenging to find, recruit and retain.

10.  Third party desktop software - it's no longer the operating system that presents the greatest risk, but security holes in Java and Adobe products such as Flash.

Security is journey and you'll never be done.  The hope is that your risk profile improves over time as more  of the environment is locked down, creating a restrictive rather than permissive infrastructure which makes services available by exception to the minimum extent necessary while balancing security and ease of use.   As I've said before, this is a Cold War at a time when Meaningful Use encourages more data sharing and breach reporting/regulatory penalties are increasingly severe.   All you can do is your best, given fixed resources and time.   And try to get some sleep.

Comments

Popular posts from this blog

clip on magnetic sunglasses visit here

Save with prescription glasses and sunglasses. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! -GlassesPoint. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! Free magnetic clip on with every pair of glasses.  The operator should contact lens Plano glasses a few days of Sun and Rx on the other person. Many people choose single vision lenses, designed for a specific use, such as prescription sunglasses. Clip-ons magnetic magnetic clip ons often come with their prescription glasses frames. Prescription glasses Goggles4u dollars from 29.99 with free shipping. Takumi neodium magnet glass features recipes that are light, strong and in. The combination of some normal prescription glasses and a pair of polarized glasses that glare-resistant to outdoor activities. clip on magnetic sunglasses visit here

The Tragedy of Underfunded Mental Health Care

Today’s Managing Health Care Costs Indicator is   19,900 The NY Times  on Friday had a deeply disturbing article on a murder that stunned the mental health community here in Massachusetts.    A long-term schizophrenic man, off his medicine and spiraling into incoherence, killed a young female counselor who was the sole worker at a group home in a Boston suburb.   His mother, who works at a Boston teaching hospital, was frantic with worry as her adult son, who had been arrested for assault multiple times, was becoming more psychotic.    It was hard for her to get anyone’s attention. The counselor was the first in her family to get a college degree, and had just decided to go to nursing school.    Now she’s dead – and her family had trouble scraping together the resources for a burial.   The schizophrenic will be imprisoned for the rest of his life – which ironically could be the best chance for him to get appropriate medical care. Both...

How a Well-Intended FDA Policy on Colchicine is Harming Patients

The road to hell is paved with good intentions. The FDA has reaffirmed the truth of this aphorism with its policy about Colchicine. Here's the story: I recently spoke with a friend who has a family member suffering from Familial Mediterranean Fever (FMF), an auto-inflammatory disorder, most commonly seen in eastern Mediterranean populations. The condition is characterized by recurrent painful inflammation of the abdomen, chest and joints, accompanied by fever. FMF is associated with mutation of a gene on chromosome 16 involved with regulating Pyrin, a protein that is part of the inflammatory response. There is no specific test for the disease. Diagnosis is made on the basis of symptoms, family history, and ruling out other conditions. Since the 1960s, Colchicine, a plant extract first used for treatment of gout two thousand years ago, has been used for treating FMF. As an ancient treatment widely used prior to formation of the FDA, Colchicine did not require FDA approval as a new ...