Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

12/11/2008
11:50 AM
George V. Hulme
George V. Hulme
Commentary
50%
50%

President-Elect Barack Obama Offers InfoSec Bailout Plan

While the president-elect may not realize it's what he's working on -- he is. And savvy security vendors already should be revamping their marketing plans for the InfoSec Stimulus Package of 2009.

While the president-elect may not realize it's what he's working on -- he is. And savvy security vendors already should be revamping their marketing plans for the InfoSec Stimulus Package of 2009.Imagine what a new PCI DSS (Payment Card Industry Data Security Standard, for those of you who have been sleeping in class) or even a re-invigorated HIPAA (Health Insurance Portability and Accountability Act) would do to give the information security community a caffeinated jolt out of its malaise?

But that's what is coming, and the thought struck me like a double shot of RedBull while I was drafting this post about the president-elect's plans to add health IT to any stimulus package he crafts with Congress for signing come Jan. 20.

Here's the paragraph, from this Sunday's radio address, that got my synapses sparking:

In addition to connecting our libraries and schools to the Internet, we must also ensure that our hospitals are connected to each other through the Internet. That is why the economic recovery plan I'm proposing will help modernize our health care system -- and that won-t just save jobs, it will save lives. We will make sure that every doctor's office and hospital in this country is using cutting-edge technology and electronic medical records so that we can cut red tape, prevent medical mistakes, and help save billions of dollars each year.

Do you see that? Hospitals interconnected on the Internet. That's a long-winded way to spell RISK. Because, when you airdrop a crate of technology on a segment of the economy that's not accustomed to managing it, well, you're going to get a certain amount of mayhem.

There will be breaches. There will be servers with years of patient data on them stolen, and that data unencrypted. There will be doctors and other health care workers transferring patient data to USB drives, only to drop them in the parking lot to be found by a reporter working at the local newspaper. There's liable to be a marked increase in medical identity theft. There may even be a few stories of systems crashing and years of patient records left unrecoverable.

That is, unless this entire Health IT initiative is done right. That will happen if the big spirit of HIPAA meets the gory details prescribed by the PCI data security standard and infosec gets baked in from the jump.

But even if that doesn't happen right away, it's sure to happen after the new Health IT superhighway experiences a number of data wrecks. And the regulatory aftermath just may be the shot of B-12 the IT security market needs to get its mojo back.

(Now, don't get me wrong, I'm quite bullish on health IT. And I'm a big fan of electronic medical records. I often write about that over here. This stuff just needs to be handled with care, and deployed right.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Human Nature vs. AI: A False Dichotomy?
John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: -when I told you that our cyber-defense was from another age
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15073
PUBLISHED: 2019-11-20
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVE-2019-15072
PUBLISHED: 2019-11-20
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVE-2019-15071
PUBLISHED: 2019-11-20
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail syste...
CVE-2019-6176
PUBLISHED: 2019-11-20
A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
CVE-2019-6184
PUBLISHED: 2019-11-20
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.