Standarding the Secure Deployment of Medical Devices

Director of Infrastructure at Interfaith Medical Center
Jul. 31, 2017
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
Standarding the Secure Deployment of Medical Devices
1 of 21

More Related Content

Recently uploaded

硕士价格咨询,美国伊利诺伊理工学院毕业证文凭证书未毕买毕业证硕士价格咨询,美国伊利诺伊理工学院毕业证文凭证书未毕买毕业证
硕士价格咨询,美国伊利诺伊理工学院毕业证文凭证书未毕买毕业证rzwftutojfo
国外文凭制做{美国圣路易斯大学毕业证}代办文凭国外文凭制做{美国圣路易斯大学毕业证}代办文凭
国外文凭制做{美国圣路易斯大学毕业证}代办文凭ghjtrhr
精仿出售,怀俄明大学毕业证学位证买国外毕业证精仿出售,怀俄明大学毕业证学位证买国外毕业证
精仿出售,怀俄明大学毕业证学位证买国外毕业证hkyuyjfg
国外大学毕业证退学买,美国纽约大学毕业证成绩单买国外毕业证国外大学毕业证退学买,美国纽约大学毕业证成绩单买国外毕业证
国外大学毕业证退学买,美国纽约大学毕业证成绩单买国外毕业证hjuth564
PU毕业证成绩单PU毕业证成绩单
PU毕业证成绩单gbjfgh
diplma升学历加急购买,印第安纳州立大学毕业证学位证未毕买毕业证diplma升学历加急购买,印第安纳州立大学毕业证学位证未毕买毕业证
diplma升学历加急购买,印第安纳州立大学毕业证学位证未毕买毕业证rzwftutojfo

Recently uploaded(20)

Featured

Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesProject for Public Spaces & National Center for Biking and Walking
Staying Cool During SummerStaying Cool During Summer
Staying Cool During SummerDeborah Davis
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationErica Santiago
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools

Featured(20)

Standarding the Secure Deployment of Medical Devices

  1. STANDARDIZING THE SECURE DEPLOYMENT OF MEDICAL DEVICES Christopher Frenz

  2. Free PowerPoint Templates

  3. Free PowerPoint Templates

  4. WANNACRY Ransomware Attack of Pandemic Proportions

  5. WannaDie??? A whole new and wholly unacceptable meaning of denial of service

  6. HIPPOCRATIC OATH FOR CONNECTED MEDICAL DEVICES

  7. FDA GUIDANCE • FDA released pre and post market guidance on cybersecurity recommendations for medical devices • Guidance is a huge step in the right direction, but is currently non-binding • Even if all manufacturers comply tomorrow it will take years before all in place medical devices are replaced with more secure models

  8. SECURING THE NOW??? • How do healthcare institutions ensure that their current device deployments are done securely? • Even a device with all the security features in the world will be insecure if it is not deployed in a secure manner. What constitutes a secure medical device deployment?

  9. OWASP STANDARD • OWASP makes available a Secure Medical Device Deployment Standard • https://goo.gl/KecNw9

  10. PURCHASING CONTROLS • The best way to prevent risks from impacting your environment is to prevent them from being introduced in the first place • Security Audit • Privacy Audit • Support • List of software components

  11. PERIMETER DEFENSES • Medical devices should be denied access to the outside world wherever feasible • Firewalls • Network Intrusion Detection • Proxy/Web Filter

  12. NETWORK SECURITY CONTROLS • Do these devices really need to communicate with every other device on your network? The answer is NO!!! • Network Segmentation • Internal Firewalls • Internal NIDS • Syslog Server • Log Monitoring • Vulnerability Scanning • DNS Sinkholes

  13. DEVICE SECURITY CONTROLS • Change default credentials • Account Lockout • Enable Secure Transport • Spare copy of firmware • Backup of device configs • Baseline configurations • Encrypt Storage • Different User Accounts • Restrict Access to Management Interface • Update Mechanisms • Compliance Monitoring • Physical Security • Asset Management What are the security controls that should be configured on the devices themselves?

  14. INTERFACES AND CENTRAL STATIONS • Computers and servers are often used to collect data and transmit data to other systems in the environment. These need to be secures as well. • OS Hardening • Encrypted Transport • Message Security • Updates

  15. SECURITY TESTING AND INCIDENT RESPONSE • Prove your deployments are secure and that you can really respond to an issue if it arises • Pen Tests • Incident Response Plan • Mock Incidents

  16. GROWING ADOPTION • Standard Covered in publications such as CSO Magazine, IAPP Privacy Perspectives, HelpNet Security, Health System CIO • Turkish Language translation recently donated by Erdal Yildiz

  17. OWASP ANTI-RANSOMWARE GUIDE • A defense in depth based guide consisting of 45 suggested controls in the following categories • Perimeter Defenses • Network Defenses • Endpoint Defenses • Server Side Defenses • SIEM and Log Management • Backup and Recovery • Awareness Training • Incident Response • IoT https://goo.gl/uOGAtZ

  18. QUESTIONS • https://www.linkedin.com/in/christopherfrenz/ Thanks to Liz Belousov, Tony Alas, Bev Corwin, Erdal Yildez