Life Sciences & Health Care, Medical Device Manufacturing - Cybersecurity Strategy

The Life Science and Health Care (LSHC) – Market presents great opportunities. This article introduces foundational regulatory and cloud frameworks knowledge that would assist cybersecurity and regulatory professionals. Topics cover Frameworks, Standards & Tools, necessary for a CISO wishing to address MDM Cybersecurity, followed by insights regarding Mapping and Tagging, EnterpriseGRC Solutions Unification within GRC, and Cybersecurity Risk Management.

Here's the PDF download for the presentation and two options for viewing, as the slides only, or as the presentation delivered to ISC2 East Bay in August of 2019.

Just the slides (because silence is golden). If you want a discussion, it's on the next page.

Live discussion (2 hours, so proceed with caution!)

Life Sciences & Health Care Medical Device Manufacturing and Cybersecurity

(This presentation was created in the first year of the Pandemic. As we start year three, it's become more relevant.)

As the Pandemic moves to its sixth month, we see a shift not only in our prioritization of health issues but how we do medicine and the implications of cybersecurity across the proliferation of attack services ranging from devices to home computing.

  • Life Science and Health Care (LSHC) – Market, Players, Opportunities
  • Two key documents for learning – BSI Cybersecurity of Medical Devices; MDIC Medical Device Cybersecurity Report
  • Cyber Related Standards
  • Frameworks, Standards & Tools, How CISO’s Address MDM Cybersecurity
  • List of resources and Laws
  • IoT and CCPA
  • Mapping and Tagging – Unification within GRC and Cybersecurity Risk Management
  • Integration Progress – Facilitated Compliance Management
  • Investment in Licenses and Partners

(Your Presenter: Hey, this is me!)

Robin Basham is the owner EnterpriseGRC Solutions, President, ISC2 East Bay, Certified Information Systems Security (CISSP), Audit (CISA), Governance (CGEIT) and Risk (CRISC-N.A), ICT GRC expert and early adopter in both certifying and offering certification programs for Cloud Security and Virtualization, with industry experience in the management of systems, controls and data for SaaS (IaaS and PaaS), Finance, Healthcare, Banking, Education, Defense, and High Tech. Positions held include Technology Officer at State Street Bank, Leading Process Engineering for a major New England CLEC, Sr. Director Enterprise Technology for multiple advisory firms, founding, engineering product and running two governance software companies, and most recently Director Enterprise Compliance for a major player in the mortgage industry, Ellie Mae. Having served as Cisco, Unified Compliance, and ISMS Program Manager for a multi-year GRC project, Robin currently leads EnterpriseGRC Solutions LSHC initiative in support of three MDM clients. Robin may also be recognized for donating substantial time to supporting social platform security to further social democracy. Robin is also a past board member for the ISACA SV chapter.

Graphical representation that everyone asks for, so here they are:

Defense In Depth NHS view
Defense In-Depth, NHS View

Life Science & Health Care EnterpriseGRC Methodology

Products Necessary to GDPR

Main Menu