Aetna CISO: Healthcare must take risks to lessen security risk

From: HealthITSecurity

Author Name Patrick Ouellette  

BOSTON – Jim Routh, Aetna Chief Information Security Officer (CISO) challenged today’s HIMSS Privacy and Security Forum audience to take risks in order to manage risks more effectively.

During his keynote, Routh said that compliance with federal regulations alone will not be sufficient in light of today’s cybersecurity threats. He compared a risk-based security program model to a compliance-based one and explained how there’s a great deal of volatility and fraud, with some subset of that fraud is directly related to cybersecurity. When Routh arrived at Aetna a year and a half ago, he received a compliance-driven program and has since implemented a risk-based program. Routh said there’s been a fundamental shift in what drives security programs.

Building your security program around regulatory requirements [alone] is no longer enough because the threat landscape is changing far too quickly. In a risk-driven program, you base everything off of the analysis of threats and changes in the threat landscape. You need to reallocate resources based on those changes, not regulations.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *