1 min read

Shared responsibility - Understanding how to share control responsibility in the cloud - HITRUST 2019

Three panelists presenting on shared responsibility at HITRUST 2019 conference

During day two of the HITRUST 2019 conference yesterday, I attended a panel called Shared Responsibility - Understanding How to Share Control Responsibility in the Cloud.

The panel was composed of:

  • Becky Swain: Director, Standards Development, HITRUST
  • Kurt Hagerman: CxO Advisor, Cyber Strategy, Coalfire
  • Blaise Wabo: Senior Manager, A-LIGN

 

It was moderated by Mike Annand: Director of Customer Compliance at Armor Cloud Security.

Shared Responsibility - Understanding How to Share Control Responsibility in the Cloud - My Takeaways

 

Conference panel on shared responsibility in cloud security with audience members at tables with laptops

Here are my takeaways:

  • “There’s no such thing as perfect security.” (Kurt Hagerman)
  • What does it mean to share responsibility?
  • Becky stressed the need to start a dialogue around similar language
  • Who owns the control and how is it written? Is it relevant to the organization?
  • The whole idea is to provide clarity to customers, providers and assessors
  • “Cloud is the new version of I.T.” (Kurt)
  • AWS IAM was used as an example of joint control ownership
  • Becky is looking for more members to the work group
  • “Once we’re speaking the same language, then we can have a healthy dialogue.” (Becky Swain)
  • A draft of the shared responsibility matrix is still in the works
  • The working group is in the middle of a reboot
  • Cost model: No additional cost to HITRUST applicants
  • Looking at version 10 having this functionality
  • “Their business is about security.” Becky on cloud vendors like AWS
  • “People are the biggest security risk.” (Becky)

See also: Streamlining Your Third-Party Risk Management Program – HITRUST 2019

Attendees and panelists at HITRUST 2019 Conference discussion on cloud security and shared responsibility

HITRUST 2019 Conference

 

Panel discussion on shared versus joint control ownership at HITRUST 2019 conference

HITRUST 2019 positions itself is the most comprehensive and definitive information risk management conference for privacy, security, and compliance professionals. The conference is held at the Gaylord Texan Resort in Grapevine, Texas.

 

Try Paubox Email Suite for FREE today.
Press release graphic announcing Paubox joining HITRUST program

1 min read

Paubox joins HITRUST Shared Responsibility and Inheritance Program

San Francisco, CA,April 28, 2021 — Paubox, a market leader in the HIPAA compliant email space, announced today that it has successfully become a...

Read More
Neon red and blue security locks and briefcases on digital code background

Who is responsible for a data breach?

Aptihealth, a behavioral healthcare provider, recently notified nearly 20,000 patients of a data breach that occurred at Sisense, an Aptihealth data...

Read More
HITRUST CSF Certified logo

How to take advantage of the HITRUST Shared Responsibility and Inheritance Program

Because of the sensitive nature of medical care, the healthcare industry faces unique security challenges. The Health Insurance Portability and...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.