WASHINGTON - The Cybersecurity and Infrastructure Security Agency published a Cybersecurity Advisory, Enhancing Cyber Resilience: Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment, detailing the agency's key findings and activities during a Risk and Vulnerability Assessment conducted at a healthcare and public health organization in early 2023.
The advisory also provides network defenders and software manufacturers recommendations for improving their organizations' and customers' cyber posture, which reduces the impact of follow-on activity after initial access.
The CISA assessments team identified several findings as potentially exploitable vulnerabilities that could compromise the confidentiality, integrity, and availability of the tested environment.
Tailored for HPH organizations of all sizes as well as for all critical infrastructure organizations, the advisory provides several recommended mitigations mapped to 16 specific cybersecurity weaknesses identified during the RVA. Also, the advisory provides three mitigation strategies that all organizations should implement: Asset management and security, Identity management and device security, and Vulnerability, patch, and configuration management.
Each strategy has specific focus areas with details and steps on how HPH entities can implement them to strengthen their cybersecurity posture.
This advisory builds on the CISA and Health and Human Services Healthcare Cybersecurity Toolkit and CISA's Mitigation Guide for HPH Sector that were recently released.
The recommended mitigations for network defenders are mapped to the Cross-Sector Cybersecurity Performance Goals.
The recommended actions for software manufacturers are aligned to the recently updated, Principles and Approaches for Secure by Design Software, a joint guide co-sealed by 18 U.S. and international agencies.
It urges software manufacturers to take urgent steps necessary to design, develop, and deliver products that are secure by design.
About CISA. As the nation's cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to understand, manage, and reduce risk to the digital and physical infrastructure Americans rely on every hour of every day.
This Cyber News was published on www.cisa.gov. Publication date: Fri, 15 Dec 2023 18:13:04 +0000