Le Lézard
Classified in: Health, Science and technology
Subject: LAW

HITRUST Responds to White House RFI for Harmonization of Cyber Frameworks


HITRUST comments that harmonization through public and private industry partnership requires appropriate assurance for consistent outcomes

FRISCO, Texas, Oct. 30, 2023 /PRNewswire/ -- HITRUST, the information risk management, standards, and certification body, today submitted comments in response to the White House Request for Information (RFI) on Cyber Regulatory Harmonization.

HITRUST Responds to White House RFI for Harmonization of Cyber Frameworks

The Office of the National Cyber Director (ONCD) invited public comments to identify opportunities and challenges to harmonize cybersecurity regulations for critical infrastructure. The RFI aims to create a harmonization framework that represents reciprocity of baseline cyber requirements that are aligned across all critical infrastructure sectors. Harmonization?which the RFI defines as, "a common set of updated baseline regulatory requirements that would apply across sectors"?is a complex, yet achievable undertaking.

Since its founding in 2007, HITRUST has championed programs that safeguard sensitive information and manage information risk for organizations in the healthcare and public health (HPH) sector, other critical and non-critical industries, and throughout the third-party supply chain in both the U.S. and internationally. Practical and achievable harmonization is fundamental to HITRUST, and the HITRUST CSF is continuously updated with more than 40 authoritative sources, including National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, NIST SP 800-171, International Standards Organization and International Electrotechnical Commission (ISO/IEC) Standard 27001 (ISO/IEC 27001), and Health Insurance Portability and Accountability Act (HIPAA) security requirements.

HITRUST provided feedback to questions on the opportunities and challenges to harmonize cybersecurity regulations based on its 15+ years of experience supporting, reviewing, and certifying thousands of security assessments for healthcare and other critical infrastructure sectors. 

"While voluntary approaches to securing critical infrastructure have resulted in measurable improvement, they have not proven consistent across all critical infrastructure sectors or even within them," said Robert Booker, Chief Strategy Officer, HITRUST. "HITRUST's experiences, and those of the hundreds of security assessor firms with whom we work, demonstrate that the issue for cyber harmonization is not the standards and regulations alone. We suggest that high-quality, robust and consistent assurance mechanisms are equally important, if not more important, to achieving adequate and consistent cybersecurity outcomes for all security regulations. Outcomes are only achieved where results are evaluated and measured."

HITRUST's experience suggest that a harmonization framework requires:

"Quality and transparency from companies issuing security certifications is essential to achieving the stated goals of harmonization and are the foundation of HITRUST assurances," said Booker. "The benefits of cybersecurity from a harmonized framework must include mechanisms for practical implementation, controls to be selected and specifically applied, and implementation maturity to be transparently scored."

For additional perspective visit HITRUST's Harmonization of Cyber Frameworks Executive Summary here.

About HITRUST

Since it was founded in 2007, HITRUST has championed programs that safeguard sensitive information and manage information risk for organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security, and risk management leaders from the public and private sectors, HITRUST develops, maintains, and provides broad access to its widely adopted common risk and compliance management frameworks as well as related assessment and assurance methodologies. For more information, visit www.hitrustalliance.net.

For media inquiries:?
Leslie Kesselring
Kesselring Communications for HITRUST
[email protected]
503-358-1012

SOURCE HITRUST Services Corp.


These press releases may also interest you

4 mai 2024
UroGen Pharma Ltd. , a biotech company dedicated to developing and commercializing innovative solutions that treat urothelial and specialty cancers, today announced results from a new analysis of the ATLAS trial, which estimates using Kaplan Meier...

4 mai 2024
UroGen Pharma Ltd. , a biotech company dedicated to developing and commercializing novel solutions that treat urothelial and specialty cancers, today highlights the results of a sub-analysis from a real-world patient cohort review of JELMYTO...

4 mai 2024
Women's Heart Health Month is recognized every May and is focused on raising awareness about cardiovascular health among women. It aims to educate women about the risks, symptoms, and prevention of heart disease, which is the leading cause of death...

4 mai 2024
RaySearch Laboratories AB (publ) and C-RAD are pleased to announce a collaboration agreement, aiming at jointly developing innovative solutions and products to enhance the quality of radiation therapy. The focus of the collaboration is to...

4 mai 2024
SecondOpinionExpert, Inc. (SOE), a leading healthcare technology company, announced today that OC Fertility® + OC Biogenix® located in Newport Beach, Orange County, California will join SOE's expert panel to provide second opinions for fertility...

4 mai 2024
Scientology Network's VOICES FOR HUMANITY, the weekly series presenting heroic change makers from a variety of faiths, cultures and nations, working to uplift their communities, announces a new episode featuring anti-drug activist Robert Galibert....



News published on and distributed by: