share_log

HITRUST Enhances Cyber Threat Adaptive Engine Using Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence

HITRUST Enhances Cyber Threat Adaptive Engine Using Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence

HITRUST 使用微软 Azure OpenAI 服务和微软 Defender 威胁情报增强网络威胁自适应引擎
PR Newswire ·  05/01 14:06

Collaboration Accelerates Framework Updates to Address Emerging Cyber Threats

协作加速框架更新以应对新出现的网络威胁

FRISCO, Texas, May 1, 2024 /PRNewswire/ -- HITRUST, a leader in information security, risk, and compliance assurance, today announced a comprehensive update to its Cyber Threat Adaptive engine to enable increased accuracy and timeliness of HITRUST CSF updates to address emerging cyber threats. This update introduces advanced AI capabilities through a collaboration with Microsoft, integrating Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence. This strategic update further advances HITRUST's ability to provide adaptive assurance solutions that are among the most relevant and reliable available, empowering organizations to effectively manage internal and third-party cyber risks.

得克萨斯州弗里斯科,2024 年 5 月 1 日 /PRNewswire/ — HITRUST是信息安全、风险和合规保障领域的领导者,今天宣布全面更新其网络威胁自适应引擎,以提高HITRUST CSF更新的准确性和及时性,以应对新出现的网络威胁。此更新通过与微软的合作引入了先进的人工智能功能,集成了微软 Azure OpenAI 服务和微软 Defender 威胁情报。此次战略更新进一步提高了HITRUST提供自适应保障解决方案的能力,这些解决方案是现有最相关和最可靠的解决方案之一,使组织能够有效地管理内部和第三方的网络风险。

Today's constantly evolving cyber threat landscape demands information security, risk, and privacy frameworks and their assurances methodologies be adaptive and relevant to the current and emerging cyber threats and information risks. Threat actors continually modify their attack methods to defeat the latest defense strategies and to take advantage of dated or ineffective standards or best practices, which have extended development and release cycles in most cases in excess of a year. To address this issue, HITRUST pioneered Cyber Threat Adaptive, a patent-pending engine to analyze cyber threat intelligence, breach, and loss data against the control specifications in the HITRUST CSF to ensure that the cybersecurity control specifications in the framework are appropriate to address current and emerging cyber threats. This approach enables HITRUST to add, remove, or modify controls specifications to maintain maximum relevance and effectiveness in managing cyber risk.

当今不断变化的网络威胁格局要求信息安全、风险和隐私框架及其保障方法具有适应性,并与当前和新出现的网络威胁和信息风险相关。威胁行为者不断修改其攻击方法,以打败最新的防御策略,并利用过时或无效的标准或最佳实践,在大多数情况下,这些标准或最佳实践将开发和发布周期延长了一年以上。为了解决这个问题,HITRUST率先推出了Cyber Threat Adaptive,这是一种正在申请专利的引擎,用于根据HITRUST CSF中的控制规范分析网络威胁情报、泄露和丢失数据,以确保框架中的网络安全控制规范适用于应对当前和新出现的网络威胁。这种方法使HITRUST能够添加、删除或修改控制规范,以保持管理网络风险的最大相关性和有效性。

Key upgrades to the Cyber Threat Adaptive engine include:

网络威胁自适应引擎的关键升级包括:

  1. Beginning the shift of its generative AI technology to Microsoft Azure OpenAI Service, enhancing, and accelerating analytical capabilities to align control requirements with the latest threat intelligence.

  2. The addition of Microsoft Defender Threat Intelligence for an expanded set of tested indicators of attack and compromise.
  3. Cross-referencing MITRE ATT&CK's tactics, techniques, and procedures (TTPs) to requirements in the HITRUST CSF.

  4. Transition to high frequency analysis (up from the previous quarterly review cycle) to inform HITRUST assessments and threat bulletins.
  1. 开始将其生成式人工智能技术转移到微软Azure OpenAI服务,增强和加快分析能力,使控制要求与最新的威胁情报保持一致。

  2. 增加了 Microsoft Defender 威胁情报,以扩展一组经过测试的攻击和入侵指标。
  3. 将 MITRE ATT&CK 的战术、技巧和程序 (TTP) 与 HITRUST CSF 中的要求进行交叉引用。

  4. 过渡到高频分析(高于上一季度审查周期),为HITRUST评估和威胁公告提供信息。

Recently, the company revealed in its inaugural Trust Report that less than 1% of HITRUST certified environments experienced a breach over the past 2 years. The company attributes much of its breakthrough performance to the relevance of its control set and Cyber Threat Adaptive engine. The company further notes that the HITRUST CSF versions 11.2 and 11.3 cover 100% of the addressable TTPs (Tactics, Techniques, and Procedures), in the MITRE ATT&CK framework.

最近,该公司在首次亮相时透露 信任报告 在过去的两年中,只有不到1%的HITRUST认证环境经历了漏洞。该公司将其突破性性能在很大程度上归因于其控制集和网络威胁自适应引擎的相关性。该公司进一步指出,HITRUST CSF版本11.2和11.3涵盖了MITRE ATT&CK框架中100%的可寻址TTP(战术、技术和程序)。

"We are particularly impressed with how HITRUST regularly updates its prescriptive controls in response to the shifting threat landscape. This is something the cyber insurance community collectively ventures to accomplish through application revamps, but these can feel static against the pace at which threats change. Cyber Threat Adaptive not only enhances our depth of knowledge around actual threats in the wild but can also aid in tailoring commercial insurance products to withstand these risks," said Sidney Passe, Partner at McGill and Partners, a specialty cyber insurance broker.

“HITRUST定期更新其规范性控制措施以应对不断变化的威胁格局,这给我们留下了特别深刻的印象。这是网络保险界共同努力通过应用程序改造来实现的目标,但与威胁变化的速度相比,这些目标可能会保持不变。Cyber Threat Adaptive不仅可以增强我们对野外实际威胁的了解深度,还可以帮助量身定制商业保险产品以抵御这些风险。” 专业网络保险经纪公司McGill and Partners的合伙人西德尼·帕斯说。

The enhancements to the Cyber Threat Adaptive program not only aim to provide immediate insights into vulnerabilities and mitigative guidance, but also lay the groundwork for future tools that will enable organizations and their vendors to conduct in-depth control assessments relative to specific threats.

网络威胁自适应计划的增强不仅旨在提供对漏洞的即时见解和缓解指导,还旨在为未来的工具奠定基础,这些工具将使组织及其供应商能够对特定威胁进行深入的控制评估。

Robert Booker, Chief Strategy Officer at HITRUST, emphasized the importance of this update, stating, "Adapting to the rapid pace of cyber threats is critical for maintaining effective standards and frameworks and it is imperative to maintaining trust. Our collaboration with Microsoft and the integration of their threat intelligence and generative AI technologies marks a significant advancement in our ongoing commitment to this goal."

HITRUST首席战略官罗伯特·布克强调了此次更新的重要性,他说:“适应网络威胁的快速发展对于维持有效的标准和框架至关重要,也是维持信任的必要条件。我们与微软的合作以及他们的威胁情报和生成人工智能技术的整合,标志着我们对这一目标的持续承诺取得了重大进展。”

"Microsoft is committed to empowering organizations to combat cyber threats through innovative solutions. Collaborating with HITRUST in enhancing its Cyber Threat Adaptive engine reflects our shared goal of advancing cybersecurity intelligence and technology," said David Houlding, Director, Global Healthcare Security and Compliance Strategy at Microsoft.

“微软致力于通过创新的解决方案增强组织对抗网络威胁的能力。与HITRUST合作增强其网络威胁自适应引擎反映了我们推进网络安全情报和技术的共同目标。” 微软全球医疗安全与合规战略董事戴维·霍尔丁说。

About HITRUST

关于 HITRUST

HITRUST, the leader in information security, risk, and compliance, offers a certification assurance program for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company's threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling the entire process and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

HITRUST是信息安全、风险和合规领域的领导者,根据50多个标准和框架,为安全、隐私和人工智能控制的应用和验证提供认证保证计划。该公司的威胁自适应方法提供了最相关和最可靠的解决方案,包括多个可选择和可遍历的控制集、100多家独立评估公司、集中式质量审查和认证,以及支持整个流程和生态系统的强大SaaS平台。在过去的17年中,HITRUST一直处于保险行业的领先地位,如今已被广泛认为是建立、维护和展示风险管理和合规安全能力的最值得信赖的解决方案。

For more details about HITRUST and its innovative approach to cybersecurity assurance, visit .

有关 HITRUST 及其网络安全保障创新方法的更多详细信息,请访问 。

For media inquiries, please contact:

媒体垂询,请联系:

Leslie Kesselring

莱斯利·凯瑟林

Kesselring Communications for HITRUST

HITRUST 的 Kesselring 通讯

[email protected]

[电子邮件保护]

503-358-1012

503-358-1012

SOURCE HITRUST Services Corp.

来源 HITRUST 服务公司

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发