Presentation is loading. Please wait.

Presentation is loading. Please wait.

Action Tracker · Status Report | Bill Moss, Assistant Secretary Oct 6, 2015 Aging and Long-Term Support, Administration Background Group Topic / Strategic.

Similar presentations


Presentation on theme: "Action Tracker · Status Report | Bill Moss, Assistant Secretary Oct 6, 2015 Aging and Long-Term Support, Administration Background Group Topic / Strategic."— Presentation transcript:

1 Action Tracker · Status Report | Bill Moss, Assistant Secretary Oct 6, 2015 Aging and Long-Term Support, Administration Background Group Topic / Strategic Plan Goal / Other Mission Critical Goals Sub Topic / Strategic Objective: Increase IT security support to improve and enhance data security to perform oversight activities to ensure evidence of compliance for both internal and external business partners statewide with data security requirements mandated by state and federal laws, DSHS Administrative and Washington State Office of Chief Information Officer (OCIO) security standards and policies, and Health and Human Services (HHS), Office of Civil Rights (OCR) DSHS investigation findings. Strategic Objective # : 4.2 Measure Title : Reduce the monthly security vulnerabilities weighted score by 5 percent for servers and workstations through June 2017. ID#Problem to be solvedStrategy/Approach Task(s) to support strategyLeadStatusDueExpected OutcomePartners 4.2.1Contractor Compliance Verification Conduct onsite compliance verification reviews with ALTSA & Developmental Disabilities Administration (DDA) contractors. Develop Compliance Verification (CV) policy & procedure, to include schedules and develop tool for CV reviews. Conduct communications about new process to ALTSA & DDA programs. Kim AndersonOn track12/31/15Ensure contractors are complying with the data security requirements of their contracts in turn keeping DSHS data protected and reducing risk of data breaches.. ALTSA & DDA Contractors 4.2.2Vulnerability Management Statewide Conduct vulnerability scans and timely patching on computer systems. Address vulnerability scans backlog to reach maintenance mode Scott DeMeyerIn progress12/31/2015Reduce or remove vulnerabilities and ensure compliance of HIPAA, state and federal regulations for protecting data. Conduct monthly and more if needed vulnerability scans on systems, applications, and data bases timely Each month through 6/30/2017 Provide oversight and track progress on corrective action plans to completion. 6/30/16 On track10/30/15Regularly updated data for reporting Collect vulnerability data to support monthly reporting. Proposed Action Type of Status Report Strategic Plan SO-4.2IT Security Vulnerability Last modified 10/06/2015 1

2 Action Tracker · Status Report | Bill Moss, Assistant Secretary Oct 06, 2015 Aging and Long-Term Support, Administration Background Group Topic / Strategic Plan Goal / Other Mission Critical Goals Sub Topic / Strategic Objective: Increase IT security support to improve and enhance data security to perform oversight activities to ensure evidence of compliance for both internal and external business partners statewide with data security requirements mandated by state and federal laws, DSHS Administrative and Washington State Office of Chief Information Officer (OCIO) security standards and policies, and Health and Human Services (HHS), Office of Civil Rights (OCR) DSHS investigation findings. Strategic Objective # : 4.2 Measure Title : Reduce the monthly security vulnerabilities weighted score by 5 percent for servers and workstations through June 2017. ID#Problem to be solvedStrategy/Approach Task(s) to support strategyLeadStatusDueExpected OutcomePartners 4.2.3Security Log Monitoring for compliance with HIPAA regulations, Office of Chief Information Officer (OCIO) IT standards and DSHS Information Security Polies Security Log Monitoring on headquarters servers that store Category 3 and 4 data. Develop documented procedure, schedules, timelines. Kim AndersonOn track6/30/16Increased security compliance required by HIPAA regulations, OCIO IT standards and DSHS Information Security Policies 4.2.4Internal verification of compliance Conduct internal audits Conduct 1-2 random audits of ALTSA and DDA sites to determine data security compliance and risk, establish corrective action plans and track to completion. Michele WeedinOn trackEach month through 6/30/2017 Increased compliance and reduced risk to department data and IT resources. ALTSA & DDA Sites Develop policy & procedure, to include schedules and develop tool for reviews. Conduct communications about new process to ALTSA & DDA programs. Proposed Action Type of Status Report Strategic Plan SO-4.2IT Security Vulnerability Last modified 10/06/2015 2


Download ppt "Action Tracker · Status Report | Bill Moss, Assistant Secretary Oct 6, 2015 Aging and Long-Term Support, Administration Background Group Topic / Strategic."

Similar presentations


Ads by Google