Wednesday, June 27, 2012

Per my previous blogs about the Summer of Compliance, we completed our multi-week joint IS/Compliance planning effort today.  

To recap, first we listed regulatory and compliance risks and the policies/technologies needed to mitigate them.   We then assigned these projects to 3 work teams to prioritize, estimate level of effort, and assign risk scores.  

We then examined the total costs necessary to complete the prioritized projects.

The end result was that we identified 55 projects with $7.8 million dollars in capital costs.    Our FY13 capital budget for security/compliance related projects is $4.2 million so we had to reduce the list of projects by $3.6 million.

The end result is that we identified malware controls as the highest priority, followed by mobile device encryption.   All projects related to these general categories will be done first.

Other key items are data loss prevention for emails sent to commercial email providers, blocking of cloud storage services, restriction on outbound internet traffic (machines sending data to unauthorized organizations), and adaptive authentication.

Items to consider deferring due to capital expense include additional e-discovery infrastructure, network access control technologies, and enterprise mobile device management applications.  These are desirable and likely will be done next year.

The end result of this exercise  - a jointly agreed upon list of priorities, budgets, and timelines for compliance work over the next year.

With a mutual understanding of the time, scope, and resources, we can triage any new requests with the perspective of the work we've already agreed to do.   Given that time and resources are known, adding scope means taking something off the list.

I look forward to the year ahead and policy/technology work needed to ensure we not only follow standard practices, but best practices.

Related Posts:

  • An Update for the Medical Executive Committee Of all the governance and oversight bodies I serve at BIDMC, the Medical Executive Committee (MEC) is one of the most important.   Here is a communication I wrote today for the MEC Newsletter which summarizes our major F… Read More
  • An Update on Controlled Substance e-Prescribing I recently had a dialog with Surescripts about the current  state of policy and technology enabling controlled substance e-prescribing.   Here's a summary:1.       Surescripts is “open for business” n… Read More
  • Building Unity Farm - the Chickens and Guinea Fowl Last week I discussed the Alpaca and Llamas, which were examined by our traveling veterinarian, Cindy Fuhs, this week and given a clean bill of health.On September 16, our chickens, now about 6 months old, began laying their … Read More
  • The September HIT Standards Committee Meeting We began the meeting by noting this was the 40th meeting of the HIT Standards Committee and the bulk of the meeting was spent thoroughly reviewing the Stage 2 ONC and CMS rules so that all members can evangelize about the acc… Read More
  • More Meaningful Use Stage 2 ResourcesTwo important resources you can use as you plan for MU Stage 2 certification and attestation.1.  The Advisory Board has prepared a poster, available to the public, comparing meaningful use Stage 1 with the Stage 2 final … Read More

0 comments:

Post a Comment

Powered by Blogger.

Popular Posts

Blog Archive