Skip to main content

Profit with Purpose in ISO 27799

$299.00
Toolkit Included:
Includes a practical, ready-to-use toolkit containing implementation templates, worksheets, checklists, and decision-support materials used to accelerate real-world application and reduce setup time.
Your guarantee:
30-day money-back guarantee — no questions asked
Who trusts this:
Trusted by professionals in 160+ countries
How you learn:
Self-paced • Lifetime updates
When you get access:
Course access is prepared after purchase and delivered via email
Adding to cart… The item has been added

This curriculum spans the breadth of a multi-workshop governance engagement, addressing the same strategic and operational decisions faced when aligning ISO 27799 with clinical workflows, regulatory demands, and enterprise risk management across a complex healthcare organization.

Module 1: Establishing Governance Foundations in Healthcare Information Security

  • Define scope boundaries for ISO 27799 compliance across clinical, administrative, and research systems within a multi-facility health network.
  • Select custodianship roles for electronic health record (EHR) data across departments, balancing clinical autonomy with centralized oversight.
  • Map regulatory requirements from HIPAA, GDPR, and local health privacy laws to ISO 27799 control objectives.
  • Determine whether to adopt ISO 27799 as a standalone framework or integrate it with an existing ISO 27001 ISMS.
  • Decide on the level of integration between clinical risk management processes and information security risk assessments.
  • Develop criteria for classifying health information (e.g., PHI, genomic data, behavioral health records) based on sensitivity and reuse potential.
  • Negotiate governance authority between IT security teams and clinical leadership during policy development.
  • Establish escalation pathways for data breaches involving third-party cloud service providers handling patient data.

Module 2: Strategic Alignment of Security Objectives with Clinical Missions

  • Reconcile clinician demands for rapid data access with security controls that enforce least privilege in emergency care settings.
  • Assess the impact of multi-factor authentication on physician workflow during patient rounds and after-hours access.
  • Align security KPIs with clinical quality metrics in performance dashboards used by executive leadership.
  • Design exception processes for temporary privilege elevation during disaster response or system outages.
  • Balance investment in cybersecurity controls against competing priorities like patient experience or EHR optimization.
  • Integrate security requirements into clinical application procurement and vendor contract negotiations.
  • Facilitate governance committee decisions on whether to allow patient portal access via personal mobile devices.
  • Coordinate with medical staff bylaws committees to enforce acceptable use policies for personal devices in clinical areas.

Module 3: Risk Assessment and Prioritization in Clinical Environments

  • Conduct threat modeling for connected medical devices (e.g., infusion pumps, MRI systems) with limited patching capabilities.
  • Assign risk ownership for legacy systems still in use due to clinical necessity, despite end-of-life status.
  • Quantify residual risk for data sharing initiatives with research partners using de-identified datasets.
  • Decide whether to accept, transfer, mitigate, or avoid risks associated with third-party telehealth platforms.
  • Adjust risk scoring models to account for patient safety implications, not just data confidentiality.
  • Document risk treatment plans that align with organizational risk appetite approved by the board.
  • Validate risk assessment outputs with input from clinical informaticists and biomedical engineering teams.
  • Update risk registers in response to changes in care delivery models, such as home-based monitoring programs.

Module 4: Policy Development and Enforcement in Regulated Healthcare Settings

  • Draft data retention policies that comply with clinical recordkeeping laws while minimizing long-term storage exposure.
  • Define acceptable encryption standards for mobile devices used by home health nurses accessing EHRs offline.
  • Enforce password policies that meet NIST guidelines without impeding access during time-sensitive clinical events.
  • Implement audit logging requirements for access to high-risk data (e.g., celebrity records, substance abuse treatment).
  • Address policy conflicts between union agreements and mandatory security training completion requirements.
  • Manage exceptions to clean desk policies in fast-paced clinical areas like emergency departments.
  • Develop sanctions frameworks for policy violations that differentiate between negligence and malicious intent.
  • Standardize policy language across affiliated hospitals to ensure consistent enforcement in a health system.

Module 5: Third-Party Risk Management for Health Data Ecosystems

  • Conduct due diligence on cloud service providers storing backup EHR data, focusing on jurisdiction and data sovereignty.
  • Negotiate business associate agreements (BAAs) that enforce ISO 27799-aligned controls with medical billing vendors.
  • Monitor compliance of research collaborators accessing limited datasets under HIPAA safe harbor provisions.
  • Assess supply chain risks for medical devices with embedded software from foreign manufacturers.
  • Implement continuous monitoring for third-party access to patient portals and API gateways.
  • Decide whether to allow subcontracting by vendors without re-approval from the data protection officer.
  • Terminate access for vendors post-contract while ensuring data return or secure destruction.
  • Establish incident response coordination protocols with third parties for joint breach investigations.

Module 6: Security Awareness and Behavioral Change in Clinical Workforces

  • Design role-based training content for non-clinical staff (e.g., billing, volunteers) with varying literacy levels.
  • Time phishing simulation campaigns to avoid interfering with peak clinical activity like shift changes.
  • Measure behavior change through observed practices, such as screen locking in shared workstations.
  • Engage physician champions to model secure communication practices in team huddles and meetings.
  • Address resistance to security practices framed as "administrative burden" by integrating messaging into clinical governance forums.
  • Customize reporting mechanisms for security incidents that fit into existing event reporting systems.
  • Track completion rates for mandatory training and link to credentialing processes for medical staff.
  • Develop just-in-time education modules triggered by access to sensitive data or new system rollouts.

Module 7: Incident Management and Response in Healthcare Contexts

  • Classify ransomware events based on impact to patient care, not just data availability.
  • Activate incident response plans that include clinical continuity teams, not just IT recovery.
  • Preserve forensic evidence from medical devices while maintaining patient safety during an ongoing procedure.
  • Coordinate public relations messaging with legal and compliance teams during a breach affecting minors.
  • Document decision-making during crisis response for later governance review and process improvement.
  • Balance transparency with patients against regulatory reporting timelines and investigation integrity.
  • Conduct tabletop exercises involving clinical leadership to test decision-making under pressure.
  • Integrate incident lessons learned into mandatory training and policy updates within 60 days of resolution.

Module 8: Audit, Monitoring, and Continuous Improvement

  • Configure SIEM rules to detect anomalous access patterns, such as off-shift logins to behavioral health records.
  • Conduct internal audits with clinical informaticists to verify control effectiveness in real workflows.
  • Respond to external audit findings from OCR or accreditation bodies with remediation plans and evidence.
  • Adjust monitoring thresholds based on seasonal variations in system usage, such as flu season.
  • Validate that automated audit logs capture sufficient detail for forensic reconstruction of access events.
  • Report control effectiveness metrics to the board using balanced scorecards that include clinical impact.
  • Rotate audit personnel to prevent familiarity bias in recurring assessments of high-risk departments.
  • Use control gaps identified in audits to prioritize annual security investment decisions.

Module 9: Governance Integration with Enterprise Risk and Compliance Programs

  • Map ISO 27799 controls to enterprise risk management (ERM) heat maps used by the executive team.
  • Integrate cybersecurity risk into capital planning processes for new hospital construction or EHR upgrades.
  • Align data governance council responsibilities with privacy and security oversight roles under HIPAA.
  • Report cybersecurity posture to the board using consistent risk language and escalation thresholds.
  • Coordinate with internal audit to avoid duplication of effort across compliance, privacy, and security reviews.
  • Embed security gate reviews into project management offices (PMOs) for clinical transformation initiatives.
  • Link control ownership to performance evaluations for department heads with significant data access.
  • Update governance frameworks in response to mergers, acquisitions, or affiliation agreements with other health systems.