share_log

HITRUST Enhances Cyber Threat Adaptive Engine Using Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence

HITRUST Enhances Cyber Threat Adaptive Engine Using Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence

HITRUST 使用微軟 Azure OpenAI 服務和微軟 Defender 威脅情報增強網絡威脅自適應引擎
PR Newswire ·  05/01 14:06

Collaboration Accelerates Framework Updates to Address Emerging Cyber Threats

協作加速框架更新以應對新出現的網絡威脅

FRISCO, Texas, May 1, 2024 /PRNewswire/ -- HITRUST, a leader in information security, risk, and compliance assurance, today announced a comprehensive update to its Cyber Threat Adaptive engine to enable increased accuracy and timeliness of HITRUST CSF updates to address emerging cyber threats. This update introduces advanced AI capabilities through a collaboration with Microsoft, integrating Microsoft Azure OpenAI Service and Microsoft Defender Threat Intelligence. This strategic update further advances HITRUST's ability to provide adaptive assurance solutions that are among the most relevant and reliable available, empowering organizations to effectively manage internal and third-party cyber risks.

得克薩斯州弗里斯科,2024 年 5 月 1 日 /PRNewswire/ — HITRUST是信息安全、風險和合規保障領域的領導者,今天宣佈全面更新其網絡威脅自適應引擎,以提高HITRUST CSF更新的準確性和及時性,以應對新出現的網絡威脅。此更新通過與微軟的合作引入了先進的人工智能功能,集成了微軟 Azure OpenAI 服務和微軟 Defender 威脅情報。此次戰略更新進一步提高了HITRUST提供自適應保障解決方案的能力,這些解決方案是現有最相關和最可靠的解決方案之一,使組織能夠有效地管理內部和第三方的網絡風險。

Today's constantly evolving cyber threat landscape demands information security, risk, and privacy frameworks and their assurances methodologies be adaptive and relevant to the current and emerging cyber threats and information risks. Threat actors continually modify their attack methods to defeat the latest defense strategies and to take advantage of dated or ineffective standards or best practices, which have extended development and release cycles in most cases in excess of a year. To address this issue, HITRUST pioneered Cyber Threat Adaptive, a patent-pending engine to analyze cyber threat intelligence, breach, and loss data against the control specifications in the HITRUST CSF to ensure that the cybersecurity control specifications in the framework are appropriate to address current and emerging cyber threats. This approach enables HITRUST to add, remove, or modify controls specifications to maintain maximum relevance and effectiveness in managing cyber risk.

當今不斷變化的網絡威脅格局要求信息安全、風險和隱私框架及其保障方法具有適應性,並與當前和新出現的網絡威脅和信息風險相關。威脅行爲者不斷修改其攻擊方法,以打敗最新的防禦策略,並利用過時或無效的標準或最佳實踐,在大多數情況下,這些標準或最佳實踐將開發和發佈週期延長了一年以上。爲了解決這個問題,HITRUST率先推出了Cyber Threat Adaptive,這是一種正在申請專利的引擎,用於根據HITRUST CSF中的控制規範分析網絡威脅情報、泄露和丟失數據,以確保框架中的網絡安全控制規範適用於應對當前和新出現的網絡威脅。這種方法使HITRUST能夠添加、刪除或修改控制規範,以保持管理網絡風險的最大相關性和有效性。

Key upgrades to the Cyber Threat Adaptive engine include:

網絡威脅自適應引擎的關鍵升級包括:

  1. Beginning the shift of its generative AI technology to Microsoft Azure OpenAI Service, enhancing, and accelerating analytical capabilities to align control requirements with the latest threat intelligence.

  2. The addition of Microsoft Defender Threat Intelligence for an expanded set of tested indicators of attack and compromise.
  3. Cross-referencing MITRE ATT&CK's tactics, techniques, and procedures (TTPs) to requirements in the HITRUST CSF.

  4. Transition to high frequency analysis (up from the previous quarterly review cycle) to inform HITRUST assessments and threat bulletins.
  1. 開始將其生成式人工智能技術轉移到微軟Azure OpenAI服務,增強和加快分析能力,使控制要求與最新的威脅情報保持一致。

  2. 增加了 Microsoft Defender 威脅情報,以擴展一組經過測試的攻擊和入侵指標。
  3. 將 MITRE ATT&CK 的戰術、技巧和程序 (TTP) 與 HITRUST CSF 中的要求進行交叉引用。

  4. 過渡到高頻分析(高於上一季度審查週期),爲HITRUST評估和威脅公告提供信息。

Recently, the company revealed in its inaugural Trust Report that less than 1% of HITRUST certified environments experienced a breach over the past 2 years. The company attributes much of its breakthrough performance to the relevance of its control set and Cyber Threat Adaptive engine. The company further notes that the HITRUST CSF versions 11.2 and 11.3 cover 100% of the addressable TTPs (Tactics, Techniques, and Procedures), in the MITRE ATT&CK framework.

最近,該公司在首次亮相時透露 信任報告 在過去的兩年中,只有不到1%的HITRUST認證環境經歷了漏洞。該公司將其突破性性能在很大程度上歸因於其控制集和網絡威脅自適應引擎的相關性。該公司進一步指出,HITRUST CSF版本11.2和11.3涵蓋了MITRE ATT&CK框架中100%的可尋址TTP(戰術、技術和程序)。

"We are particularly impressed with how HITRUST regularly updates its prescriptive controls in response to the shifting threat landscape. This is something the cyber insurance community collectively ventures to accomplish through application revamps, but these can feel static against the pace at which threats change. Cyber Threat Adaptive not only enhances our depth of knowledge around actual threats in the wild but can also aid in tailoring commercial insurance products to withstand these risks," said Sidney Passe, Partner at McGill and Partners, a specialty cyber insurance broker.

“HITRUST定期更新其規範性控制措施以應對不斷變化的威脅格局,這給我們留下了特別深刻的印象。這是網絡保險界共同努力通過應用程序改造來實現的目標,但與威脅變化的速度相比,這些目標可能會保持不變。Cyber Threat Adaptive不僅可以增強我們對野外實際威脅的了解深度,還可以幫助量身定製商業保險產品以抵禦這些風險。” 專業網絡保險經紀公司McGill and Partners的合夥人西德尼·帕斯說。

The enhancements to the Cyber Threat Adaptive program not only aim to provide immediate insights into vulnerabilities and mitigative guidance, but also lay the groundwork for future tools that will enable organizations and their vendors to conduct in-depth control assessments relative to specific threats.

網絡威脅自適應計劃的增強不僅旨在提供對漏洞的即時見解和緩解指導,還旨在爲未來的工具奠定基礎,這些工具將使組織及其供應商能夠對特定威脅進行深入的控制評估。

Robert Booker, Chief Strategy Officer at HITRUST, emphasized the importance of this update, stating, "Adapting to the rapid pace of cyber threats is critical for maintaining effective standards and frameworks and it is imperative to maintaining trust. Our collaboration with Microsoft and the integration of their threat intelligence and generative AI technologies marks a significant advancement in our ongoing commitment to this goal."

HITRUST首席戰略官羅伯特·布克強調了此次更新的重要性,他說:“適應網絡威脅的快速發展對於維持有效的標準和框架至關重要,也是維持信任的必要條件。我們與微軟的合作以及他們的威脅情報和生成人工智能技術的整合,標誌着我們對這一目標的持續承諾取得了重大進展。”

"Microsoft is committed to empowering organizations to combat cyber threats through innovative solutions. Collaborating with HITRUST in enhancing its Cyber Threat Adaptive engine reflects our shared goal of advancing cybersecurity intelligence and technology," said David Houlding, Director, Global Healthcare Security and Compliance Strategy at Microsoft.

“微軟致力於通過創新的解決方案增強組織對抗網絡威脅的能力。與HITRUST合作增強其網絡威脅自適應引擎反映了我們推進網絡安全情報和技術的共同目標。” 微軟全球醫療安全與合規戰略董事戴維·霍爾丁說。

About HITRUST

關於 HITRUST

HITRUST, the leader in information security, risk, and compliance, offers a certification assurance program for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company's threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling the entire process and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

HITRUST是信息安全、風險和合規領域的領導者,根據50多個標準和框架,爲安全、隱私和人工智能控制的應用和驗證提供認證保證計劃。該公司的威脅自適應方法提供了最相關和最可靠的解決方案,包括多個可選擇和可遍歷的控制集、100多家獨立評估公司、集中式質量審查和認證,以及支持整個流程和生態系統的強大SaaS平台。在過去的17年中,HITRUST一直處於保險行業的領先地位,如今已被廣泛認爲是建立、維護和展示風險管理和合規安全能力的最值得信賴的解決方案。

For more details about HITRUST and its innovative approach to cybersecurity assurance, visit .

有關 HITRUST 及其網絡安全保障創新方法的更多詳細信息,請訪問 。

For media inquiries, please contact:

媒體垂詢,請聯繫:

Leslie Kesselring

萊斯利·凱瑟林

Kesselring Communications for HITRUST

HITRUST 的 Kesselring 通訊

[email protected]

[電子郵件保護]

503-358-1012

503-358-1012

SOURCE HITRUST Services Corp.

來源 HITRUST 服務公司

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論