Connect with us

Technology

HITRUST Announces Continuous Assurance through the Proven HITRUST Ecosystem

Published

on

Releases 2025 Vision to Increase Security Sustainability and Outcomes through Continuous Control Monitoring

FRISCO, Texas, Oct. 1, 2024 /PRNewswire/ — HITRUST, the leading provider of information risk management, security, and compliance assurance, today announces HITRUST Continuous Assurance – the latest strategic evolution based on the proven HITRUST ecosystem. As organizations continue to balance the cost and complexity of security and compliance monitoring with the need to achieve security outcomes, a systematic and efficient approach for continuous assurance is essential. Security threats are not static and the need to efficiently reduce evidence decay and continually ensure that security requirements remain relevant and reliable is vital given the evolving threat landscape.

HITRUST Announces Continuous Assurance through the Proven HITRUST Ecosystem

“The traditional overhead and a growing number of new, proprietary and inefficient approaches trying to speed up outdated practices must fall to the side to improve cybersecurity outcomes without burdening vital services across multiple industries,” said Robert Booker, Chief Strategy Officer, HITRUST during his keynote at HITRUST Collaborate conference. “Approaches that prioritize compliance over security are understandable in highly regulated industries but are unfortunately short-sighted and part of the problem and not the solution.”

Legacy approaches do not build on a proven foundation of relevant controls, do not keep up with cyber threats, do not enable cybersecurity insurance risk underwriting as they lack provable security outcomes and validation, or assurance based on quality, transparency, and integrity. The advent of transformative technologies such as generative AI make this an even more challenging problem with new threats and vulnerabilities to overcome.

Evidence decay has always been a problem for governance systems based solely on auditing and HITRUST has largely mitigated that risk through its comprehensive and centralized quality system, rapid-recertification requirements, and the validation of policies and procedures that underpin security outcomes. In addition, the HITRUST system is built on a maturity model that encourages organizations to seek higher levels of security maturity including measurement and management of security requirements.

Continuous Assurance is possible on top of the proven HITRUST ecosystem that has successfully validated and certified thousands of systems serving multiple industries. After 15 years, HITRUST continues to demonstrate high levels of success as show by the 2024 HITRUST Trust Report where 99.4% of current HITRUST certifications, including organizations of varying sizes in many industries, did not report a breach over the past two-year period (2022 and 2023) while operating in one of the most aggressive cyber-attack environments in history. This success is enabled by the combination of the HITRUST CSF alongside a required methodology that assesses control maturity using an innovative PRISMA-based control scoring model and backed by thousands of qualified and independent assessors globally – all monitored by the centralized HITRUST quality assurance system.

“HITRUST certification at the r2 level requires a solid foundation of policy, procedures and controls implementation which provides a higher level of assurance based upon direct rather than circumstantial evidence”, said Bimal Sheth, EVP of Standards Development and Assurance Operations, HITRUST. “HITRUST is building on this proven framework as the foundation for Continuous Assurance.”

Continuous Assurance Elements:

Continuous Assurance goes the last mile – enabling integration with technologies that provide security control measurement and management. The result is unprecedented levels of assurance by minimizing evidence decay through monitoring of key assurance evidence and security telemetry on a continuous basis – all designed to detect or avoid drift in an organization’s control posture. Multiple existing and planned capabilities make Continuous Assurance possible:

Continuous Monitoring Taxonomy through the Next Generation HITRUST CSF: Control requirements require different approaches to continuous assurance to ensure relevancy and reliability of security maturity oversight. The identification of control requirements categories suitable for continuous assurance will be supported in the Next Generation of the HITRUST CSF, rolling out in phases beginning in 2025, starting with HITRUST CSF v12.Continuous Monitoring Workflow Enhancements: The HITRUST MyCSF will contain new workflow capabilities that allow assessed entities to publish evidence updates and seek validation of evidence of continued control sustainability. Inspection and approval will vary by control category and the system will support the relationships and workflow needed to analyze submitted evidence and confirm that it is both suitable for the control requirement and the underlying scope of the certification. Depending on the rigor and importance of different control requirements, External Assessors will be needed to examine and validate security outcomes and will be vital contributors to Continuous Assurance outcomes.Automated Evidence Collection: HITRUST’s existing Automated Evidence Collection capability supports integration with assessed entities existing technology and compliance frameworks. These services provide an important foundation by providing the baseline of evidence used for security and compliance assurance while reducing cost and complexity.Continuous Outcome Inspection: New HITRUST services will be available beginning in late 2025 that allow qualified service providers and technology suppliers to demonstrate proven fidelity, integrity and sufficient integration capabilities to HITRUST that inform security maturity scores and prove that security requirements remain achieved through their systems. Selected, qualified, and leading cloud service providers and security technology providers will provide these services all delivered on top of the robust and existing shared responsibility and inheritance capabilities provided by HITRUST.Results Distribution System: HITRUST’s existing digital platform enables the seamless distribution and integration of assessment and certification results, corrective action plans (CAPS), and status updates – eliminating reliance on PDF reports and allowing for electronic examination of security outcomes plus analysis of individual maturity metrics, and monitoring of remediation commitments on demand and with higher fidelity.Governance, Risk and Compliance Integration: HITRUST assessment results and assurance outcomes may now be integrated directly into supporting third-party risk management and GRC systems, ensuring faster and more accurate analysis, quicker remediation, and increased transparency, including vital Third-Party Risk Management, workflow support with improvements in efficiency, and clear and traceable documentation. 

The HITRUST Continuous Assurance system, by design, will support both systemic control monitoring through Continuous Outcome Inspection and the collection of security artifacts with validation workflows that prove conformance with required policies and procedures. Mature and complex systems will likely require a combination of automated and artifact-oriented forms of security monitoring to ensure that policies and procedures remain relevant.

Building on a Proven Ecosystem:

Continuous assurance is only achievable when delivered on top of a proven ecosystem. Over the past 15 years, HITRUST has built the ecosystem ready to deliver Continuous Assurance including:

Broad Assessment Portfolio: HITRUST offers a comprehensive range of assessment options that cover varying levels of assurance. This allows organizations and relying parties to align their risk management efforts with Threat and Adaptive Control Selection that is continuously updated as threats evolve.Cyber Threat Adaptive Controls: The HITRUST CSF is continuously updated as new cyber threats are identified and in response to active threats. This ensures organizations are continually considering the changes needed to manage their risks and sustain the required protections from the security system. Assurances only remain valid if they are implementing the correct security requirements to address present threats.Assurance Quality Management: a centralized, proven and transparent approach to quality assurance that includes examination, testing, and validation of security evidence by trained and qualified external assessors. Quality standards are published and are appropriately measured, tested, and validated first by external assessors and then by HITRUST. This ensures that the security outcomes and the resulting certification are transparent, scalable, consistent, accurate and demonstrate the integrity required by relying parties including regulators.Inheritance and Shared Responsibility: In many cases, security controls may be inherited from service providers such as Cloud Service Providers and now AI Service Providers. This capability allows assessed entities to rely on those service providers to provide components of the security fabric based upon the validation and certification of their services or to share responsibility for controls. Continuous Assurance will support the inheritance and shared responsibility of controls in appropriate use cases.

Powered by Platform Integrations:

HITRUST Continuous Assurance is building on an expanding network of integration capabilities from recognized platform and service providers. These integrations will streamline the process of managing information and cybersecurity risks and allow customers of the HITRUST ecosystem to integrate Continuous Assurance capabilities from multiple suppliers as available.

Delivering Proven Outcomes:

HITRUST Continuous Assurance delivers on top of a rich and proven maturity model. However, breaches and disruptions to services from cyber events still occur and Continuous Assurance will provide even higher security outcomes and greater levels of assurance. “The information obtained from monitoring controls in a continuous manner can help organizations continually assess the state of their information security controls and subsequently the amount of additional residual risk the organization may be incurring. Introducing more continuous, or ongoing approaches over point-in-time assessments and control gap analysis increases the fidelity of ongoing, risk-based decisions and improves cybersecurity outcomes”, said Dr. Bryan Cline, Chief Research Officer, HITRUST.

Stay Informed: 

Stay informed about Continuous Assurance here

About HITRUST

HITRUST, the leader in enterprise risk management, information security, and compliance assurances, offers a certification system for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company’s threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling its program and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

To learn more about HITRUST, go to: www.hitrustalliance.net

For media inquiries, please contact:
Leslie Kesselring
Kesselring Communications for HITRUST
leslie@kesscomm.com
503-358-1012

View original content to download multimedia:https://www.prnewswire.com/news-releases/hitrust-announces-continuous-assurance-through-the-proven-hitrust-ecosystem-302264594.html

SOURCE HITRUST Services Corp.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Groundbreaking Very Large Sleep Study Reveals Unprecedented Insights into Sleep Patterns Across Age Groups

Published

on

By

SANTA CRUZ, Calif., Oct. 1, 2024 /PRNewswire/ — Fullpower-AI®, in collaboration with Stanford University and UCSF, is proud to announce the results of a landmark study presented at the recent European Sleep Conference in Seville, Spain. This study, leveraging the Sleeptracker-AI® platform, represents the largest-ever population-based assessment of sleep duration and architecture, analyzing over 7 million nights of sleep data.

Key Findings are: 

Sleep Duration: The study reveals a U-shaped distribution of sleep duration across age groups, with middle-aged adults sleeping less than both younger and older adults.Deep Sleep and REM Sleep: Deep and REM sleep percentages decline with age. Notably, individuals with sleep apnea (AHI > 5) experience significantly reduced deep sleep across all age groups.

Age-Specific Insights:

20-25-Year-Olds: Average sleep time is 431 minutes, with 15.9% deep sleep and 26% REM sleep.0-55-Year-Olds: Average sleep time is 413 minutes, with 14.3% deep sleep and 25.7% REM sleep.80-85-Year-Olds: Average sleep time is 420 minutes, with 13.1% deep sleep and 22.9% REM sleep.

“This study provides crucial baseline data for understanding sleep patterns across the lifespan and the impact of sleep disorders,” said Philippe Kahn, Founder and CEO of Fullpower-AI®. “It underscores the importance of the 7-hour sleep recommendation and highlights how conditions like sleep apnea can significantly impact sleep quality.”

The scale and depth of this research mark a significant advancement in sleep science. These findings may shape future research and clinical practice in sleep medicine.

For more information about the study or to access detailed data, please visit sleeptracker.com.

About Fullpower-AI®

Fullpower-AI® designs, develops, and operates the Sleeptracker-AI® platform worldwide, targeting clinical trials and medical practitioners. Integrated into market-leading Tempur-Pedic smart beds, our platform offers clinical-grade accuracy comparable to gold-standard PSG.

For further details or media inquiries, contact busdev@fullpower.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/groundbreaking-very-large-sleep-study-reveals-unprecedented-insights-into-sleep-patterns-across-age-groups-302264889.html

SOURCE Fullpower

Continue Reading

Technology

Byggfakta Group becomes Hubexo and announces new leadership structure

Published

on

By

New name reflects Hubexo’s position at the center of the global construction sector.New leadership and brand structure will drive innovation and growth.Product brands remain unchanged with a refreshed identity.

STOCKHOLM, Oct. 2, 2024 /PRNewswire/ — Byggfakta Group, the parent company behind several market-leading construction data and information brands, including BCI, NBS, and Vortal, today announced that it has changed its name to Hubexo. This new identity heralds the start of a global rebranding and restructuring project to position the company as a dynamic and forward-thinking leader in the construction data and technology sector.

A new company website (www.hubexo.com) launches today. The name change only affects the parent company, although brands within the group will receive new visual identities to build a stronger link to the Hubexo brand. Customer-facing products maintain their existing names.

“The built environment shapes how we live, work, and play, and our new name reflects our commitment to connecting and shaping the global construction industry with our vital data and insights,” said Dario Aganovic, Chief Executive Officer. “We are building on almost 100 years of construction expertise, and now as Hubexo we’re unifying our global brands to drive innovation, empower our customers, and guide the construction sector into a sustainable future.” 

To reinforce its global ambitions, the Hubexo leadership team has been restructured to streamline operations and enhance innovation. The company has also appointed regional Presidents to oversee commercial operations in APAC, Northeast Europe, West Europe, UK & Ireland, and North America.

“Our new leadership structure allows us to sharpen our focus on innovation, collaboration, and customer success,” said Aganovic. “We’re creating an agile and united leadership that will deliver even better products for our customers and create a rewarding environment where our 2,500 colleagues around the world can thrive.”

The full Hubexo executive team now includes:

Dario Aganovic, Chief Executive OfficerFredrik Lundqvist, Chief Financial OfficerJoakim Percival, Chief Product OfficerLars Ryding, Chief Operating OfficerMiguel Sobral, Chief Strategy OfficerLindi Teate, Chief People OfficerAshleigh Porter, President, APACKyle Camp, President, North AmericaThomas Bejer-Andersen, President, Northeast EuropeJoanne Keit, President, UK & IrelandDario Aganovic, President, West Europe (Interim)

Hubexo will focus on its core construction data business, while the company’s non-construction operations, such as media and healthcare, will be spun out into a new entity led by Max Lagerstedt, former CEO Nordics, Byggfakta Group. Aganovic will serve as Chair.

The rebranding initiative is expected to be completed by Q2 2025, with updates to the group’s visual identity and brand communications in line with Hubexo’s vision. The Byggfakta Group website will redirect to Hubexo.com, where stakeholders can learn more about the new brand direction.

Notes for editors:

About Hubexo:
Hubexo, formerly Byggfakta Group, provides cutting-edge data, insights, and software solutions to the global construction industry. Founded in Sweden in 1936, Hubexo specializes in project information, eTendering, product information, market intelligence, and specification.  

With operations in more than 20 countries and a workforce of 2,500 employees, Hubexo helps its customers sell more efficiently, build sustainably, and lead the future of construction innovation.

Hubexo is owned by a private equity consortium of Stirling Square Capital Partners, TA Associates and Macquarie Capital. Dario Aganovic was appointed CEO in 2022.

For more information, visit: www.hubexo.com

Press contact: 

Hubexo Press Office
markst.andrew@hubexo.com
+44 7983 645 704

Logo – https://mma.prnewswire.com/media/2518252/Hubexo_Logo.jpg

View original content:https://www.prnewswire.co.uk/news-releases/byggfakta-group-becomes-hubexo-and-announces-new-leadership-structure-302262331.html

Continue Reading

Technology

Ampace will showcase its star product PU100 at the 2024 Asian Data Center Exhibition

Published

on

By

—— PU100, Protecting the Digital and Intelligent World

SINGAPORE, Sept. 30, 2024 /PRNewswire/ — With the widespread application of technologies such as cloud computing, big data, and artificial intelligence, the data center industry is experiencing unprecedented rapid development. Ampace has deeply analyzed the scenarios of computing and power demand, innovatively developed the star PU series products, which will be showcased at the largest data center event in Asia from October 9 -10th, 2024 – the Singapore DCW Asia Data Center Exhibition. (Booth D15)

The PU series embody “high security, strong performance, easy maintenance, and high cost-effectiveness”. Leveraging Ampace’s leading technical capabilities, they significantly enhance energy utilization, reduce operation costs, ensures data security and stable operation, while promoting environmental friendliness and sustainable development, redefining the new standards of the digital intelligence world.

“Ultimate safety” is the unwavering philosophy of Ampace. Since the launch the PU series products, they have maintained a record of zero safety incidents. Underpinned by the core belief that “safety is the bottom line, moreover, it is the red line”. By establishing a three-layer safety defense from material genes to system architecture, it achieves a PPB-level safety standard.

At this exhibition, Ampace’s Chief Security Expert Dr. Zhu will share insights on “ESS Product Safety Design”, conveying the safety philosophy and practices throughout the product lifecycle.

Ampace is committed to providing global users with safe, reliable, intelligent, efficient, and green new energy product applications and services. This marks Ampace’s first appearance at DCW, demonstrating a deep commitment to the Asia-Pacific data center market. Ampace looks forward to engaging with global industry elites, exchanging cutting-edge experiences, exploring cooperation potential, and working together to inject strong momentum into the green transformation and sustainable development of the data center industry.

Ampace Technology Limited (hereinafter referred to as “Ampace”) stands as a globally acclaimed innovator in new energy technologies, committed to delivering green energy solutions with ultimate user experience to forge the world ahead and empower a better life. The company is known with world class R&D and manufacturing of a complete chain Li ion battery products from “Cell-Battery Pack-System Integration”, and has obtained of authoritative certifications.

In the realm of energy storage, e-mobility, power tools, vacuum cleaners, drones, and more, Ampace has established extensive strategic partnerships with industry leaders. The company is renowned for providing new energy products and services characterized by ultimate safety, reliability, performance, and user experience, serving over 41 million customers in 29 countries and regions worldwide.

To learn more, please visit the Ampace official website: https://www.ampacetech.com/en.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/ampace-will-showcase-its-star-product-pu100-at-the-2024-asian-data-center-exhibition-302262406.html

SOURCE Ampace

Continue Reading

Trending