• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Critical aspects of information security for BFSI and Healthcare domains


By VARINDIA - 2020-07-30
Critical aspects of information security for BFSI and Healthcare domains

Ganesh Viswanathan, Senior VP-PMO & CISO, Aithent Technologies Pvt Ltd

 

 

Information Security is a critical requirement in the Banking and Healthcare industry. News abound about data theft and breaches affecting millions of customers. With increasing threat vectors and rising intensity of attacks it is important that we have a robust security framework. The article highlights the critical facets for protecting the business from various types of cyberattacks and secure the business-critical information.

 

As Banks & Financial Institutions and Healthcare providers are dealing with confidential Personally Identifiable Information (PII), Protected Health Information (PHI) it requires a high degree of safety and security. While there has been a good amount of focus on protecting the assets in terms of physical and logical security still there have been discernible gaping holes

 

1.    24 X 7 Physical Security & Surveillance: It is one of the most overlooked aspects of security. As per a 2015 study of healthcare data breaches found that physical security is the most common cause of security compromise. Hence the need for adopting a layered security strategy to protect the crown jewels which are the raison d’tre of the business.

 

2.    Risk assessment and Treatment: Risk management is a key element of information security and privacy governance. The identification, assessment and mitigation of top and emerging risks should be through a well-defined internal process through the use of appropriate Risk management policies, procedures and tools. Risk assessment should cover financial risks such as credit risk, business risk, market risk, liquidity risk and non-financial risks (NFRs) including reputational risk and operational risk. 

 

3.    Logical Security: Adequate controls need to be deployed at the desktop level to prevent any form of data leakage. To access remote applications, documents, desktops securely Citrix application is installed on all end point devices. The access to the application should be through 2 factor authentication. Besides disabling Internet services, Personal mails such as Gmail, Yahoo Mail, access to home drive should be disabled. USB and CD & DVD-ROM’s are also disabled. Right click access to save on desktop and Utilities to create, read, edit text files.

 

Operating system should be latest and supported by OEM. There should be a daily Anti-Virus signature update and patches should be deployed at least once a month. The internal and external Vulnerability scan to be conducted on a quarterly basis and all the critical and major gaps to be acted upon. For all applications Penetration Testing should be conducted and all the gaps to be fixed on an annual basis


The list of employees having privileged access to the IT Infrastructure (Application servers, database servers, database, network devices, VPN, Antivirus, Firewalls, Workstations, and Products/Applications) should be reconciled with the active employee list on the date of review by the concerned Project Manager on a monthly basis. Similarly all user access to the above IT infrastructure should be reconciled at least once in two months. 

 

4.    Social Engineering:  98% of cyber-attacks rely on social engineering. The human firewall is the weakest link in information security and deception as a technique is used by cyber criminals to manipulate the employees to divulge confidential or personal information. There are various techniques used such as Phishing (Email), Vishing (Voice), Smishing (SMS), shoulder surfing, dumpster diving , impersonation, whaling used to target the gullible employees and exploit them to break the security protocols and procedures.  
 

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.