Intelligent CISO Issue 35 | Page 50

With the right data security measures in place , all organisations involved in this effort can secure themselves against potential attackers .
FEATURE

With the right data security measures in place , all organisations involved in this effort can secure themselves against potential attackers .

database must be successful every minute of the day .
Identity and access management – the key to security success
With such a complicated and sensitive distribution process , it is vital that only those who are authorised to access data relating to the COVID-19 vaccines can do so . Identity and access management will therefore be crucial in regulating user access and preventing any unauthorised parties from accessing private information about patients or even the vaccine itself .
The first step in this security defence is understanding exactly what information is being held and where it is being stored . A comprehensive internal audit will help organisations to not only identify their data but also where it sits and , importantly , who has access to it .
Once this has been established , security controls can be implemented to provide a vital layer of defence . Encrypting data at its source will ensure that even if there is a breach of the NHS ’ s systems , the data will be rendered useless if it ends up in the wrong hands . This is regardless of whether its stored on company servers , in the public cloud or in a hybrid / multi-cloud environment . Meanwhile , the adoption of Two- Factor Authentication will ensure only authorised employees have access to the data they need and nothing else .
Under this method , the user will be asked for an extra piece of information in order to verify themselves , such as a unique code sent to them via their device . Adding Zero Trust protocols on top of this provides an extra layer of protection . This means implementing a ‘ verify but never trust ’ philosophy that restricts people to accessing only what they are authorised to . Should there be a breach , it essentially prevents hackers from accessing the wider network and the keys to the kingdom .
When implemented correctly , these security tools will protect the distribution of the COVID-19 vaccines – which is especially critical in the age of GDPR , where the loss of someone ’ s private information can result in big fines under compliance regulations .
The creation and distribution of the COVID-19 vaccines is a critical healthcare undertaking and the security of the information behind it will be of a similar importance . Lives literally depend on it , with many vulnerable people around the UK in line for the life-saving vaccine and hackers always keen to jump on a crisis . However , with the rollout going well and millions more pieces of valuable data being created every day , now is not the time to rest easy . With the right data security measures in place , all organisations involved in this effort can secure themselves against potential attackers . u
50 www . intelligentciso . com