110 likes | 131 Views
Join WHISTL to test and reduce exploitable weaknesses in medical devices. Our lab offers 3 certification levels to reduce vulnerabilities in healthcare settings. Collaborate with us to enhance cybersecurity skills and share best practices.
E N D
WHISTL World Health Information Security Testing Lab
Basics • Who: Federated Medical Device Cybersecurity Testing Laboratories • What: Test and Reduce Exploitable Weaknesses and Attacks in Medical Devices and Systems • Where: 3 Levels of Laboratory Certification • Why: Reduce Vulnerability and Threat Surface in Healthcare environments related to Medical Devices
Certification Levels • Level 1 – Verify and validate control and mitigation claims • Level 2 - Attempt to apply risk control mechanisms to validate control strategy efficacy • Level 3 - Simulates real attacks in a controlled environment to confirm or discover real or unknown vulnerabilities
University of Vermont • HTM Shared Service • Healthcare Organizations 15-500 beds • 400+ clinics • 70,000 assets
Healthcare Technology Life Cycle • Cyber Risks throughout the Lifecyle • New Installs to Patches • Assess upfront • Manage to Disposal
HTLC & WHISTL Must Identify to be able to implement controls The Focus of WHISTL
HTLC - WHISTL Lab Skill Challenge • Skill Sets Required • Clinical Engineering • IT • Cybersecurity • Training A Must! Collaboration
The Data - Challenges • Is the data? • Standardized • Comparable site to site • Complete
Data Best Practice Process • Entered at the Source • Scrubbed • Reviewed & Validated • Periodic Reviews • WHISTL will depend on good data to share
WHITSL Central Theme • Understand • Reduce • Control • Single device to population