2019/10/09 by Thomas P. Dover, Dover, Thomas P.
Computer Science · #Advanced Malware Detection Techniques #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #Digital and Cyber Forensics #FOS: Computer and information sciences #Information and Cyber Security
paper · pdf · doi:10.48550/arxiv.1910.04293
openalex publication_date 2019/10/09 · openalex created_date 2022/07/28 · openalex updated_date 2026/07/28
This paper describes how NIST Special Publications (SP) 800-171r2 (Protecting\nControlled but Unclassified Information in Nonfederal Systems and\nOrganizations), SP.800-172 (Enhanced Security Requirements for Protecting\nControlled Unclassified Information) and SP.800-172A (Assessing Enhanced\nSecurity Requirements for Controlled Unclassified Information) can be used to\nevaluate the cybersecurity posture of information systems and supporting\nframeworks relative to HIPAA and HITECH . It will demonstrate that provisions\nand baseline security requirements outlined in SP.800-171r2 and SP.800-172/172A\nfor the protection of Controlled Unclassified Information (CUI) can be applied\nto Electronic Protected Health Information (ePHI). An explanation of how these\npublications align with HIPAA and how this alignment suffices for evaluating IT\nenvironment security will be given along with the process and procedure for\nperforming such evaluation. Finally, the benefits of using this approach to\nsupport formal risk assessment will be presented.\n