GRC Academy

How HITRUST Fixes What’s Broken in Cybersecurity Compliance


Listen Later

Cybersecurity frameworks can learn a lot from HITRUST.

In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.

I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.

Here’s what stood out to me:

  • HITRUST reviews its security controls quarterly based on threat intel and control effectiveness
  • There are three distinct assessment levels (like CMMC)
  • HITRUST itself issues a certification after the 3rd party assessment and running the assessment results through two stages of QA
  • Every 3rd assessment gets reviewed. Every. Single. One.

The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.

HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.

I personally think that commercial cybersecurity frameworks should take a look at HITRUST.

What were your biggest takeaways? Let me know in the comments.

Follow Ryan on LinkedIn: https://www.linkedin.com/in/ryan-patrick-3699117a/

HITRUST Website: https://hitrustalliance.net/

-----------

Thanks to our sponsor Vanta!

Get back time to focus on strengthening security and scaling your business.

Discover the new way to GRC here: https://vanta.com/grcacademy

-----------

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e8&utm_campaign=courses

#hitrust

...more
View all episodesView all episodes
Download on the App Store

GRC AcademyBy Jacob Hill

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like GRC Academy

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,007 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,864 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

171 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

Cyberspin by Redspin

Cyberspin

0 Listeners

Sum IT Up: CMMC News Roundup by Summit 7

Sum IT Up: CMMC News Roundup

14 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

455 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Proof by Derrich Phillips

CMMC Proof

0 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners