C.3 System security Flashcards

Select system security risks and mitigation strategies.

1
Q

What significant change occurred in the Australian health sector’s cyber threat landscape in 2020?

A

68% increase in cyber security incident reports compared to 2019

This change was influenced by the Covid pandemic and various operational pressures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are some reasons for the increase in cyber security incidents in the health sector?

A

Factors include:
* New targets from non-traditional entities
* Increased operational pressure on existing organizations
* Greater attack surfaces from remote work
* Malicious actors exploiting fear and uncertainty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which sector reported the highest number of incidents to the ACSC in 2020?

A

The health sector

This sector is considered both valuable and vulnerable due to sensitive data and critical services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What percentage of health sector incidents reported to the ACSC in 2020 involved compromised systems?

A

52%

This represents an 11% increase from 2019.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is currently assessed as the most significant cybercrime threat to the Australian health sector?

A

Ransomware

This highlights the increasing risks faced by health organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What was the average number of security breaches faced by companies in 2020?

A

22 security breaches

This statistic reflects the growing cyber threat landscape.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What percentage of cyber attacks are targeted at small businesses?

A

43%

This indicates that small businesses are particularly vulnerable to cyber threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the association of human error with cybersecurity breaches?

A

Human error is associated with more than 95% of breaches

This emphasizes the importance of training and awareness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What percentage of healthcare organizations globally have experienced data breaches?

A

Around 94%

This statistic underscores the critical cybersecurity challenges in healthcare.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What key roles are often lacking in healthcare organizations, contributing to data breaches?

A

Chief Information Officer and Chief Security Information Officer

Their absence can lead to increased vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the ‘essential eight’ mitigation strategies for cybersecurity?

A

The strategies include:
* Application control
* Regular patching and updates
* Controlled macro settings
* Implementation of hardening guidance
* Restricted administrative privileges
* Prompt patching of internet-facing services
* Multi-factor authentication
* Regular backups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of the Security of Critical Infrastructure Act 2018?

A

To enhance cybersecurity across critical sectors, including health

The Act includes mandatory cyber incident reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What challenges are highlighted from the AIDH’s 2018 cybersecurity survey?

A

Challenges include:
* Lack of responsibility awareness among staff
* Low knowledge of cybersecurity policies
* Use of unsupported systems
* Insufficient business continuity testing
* Limited cybersecurity budget

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are some emerging trends in cybersecurity risk within Australian healthcare?

A

Emerging trends include:
* Vulnerabilities in medical devices
* Data confidentiality and privacy concerns
* Risks associated with cloud computing
* Security issues with health apps
* Insider threats due to ignorance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False: The healthcare sector has high cybersecurity capability maturity.

A

False

The sector is recognized as having low cybersecurity capability maturity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a significant driver for regulatory and policy oversight in healthcare cybersecurity?

A

Health information privacy and security concerns of patients/consumers

17
Q

What does ISO 27799:2016 provide guidelines for?

A

Information security management in health using ISO/IEC 27002

It supplements ISO/IEC 27002 for managing health information security.

18
Q

Fill in the blank: More than ____% of clinical staff knew their organization’s cybersecurity policies.

19
Q

What is the average cost of a healthcare data breach compared to other industries?

A

65% higher

This statistic highlights the financial implications of cybersecurity incidents in healthcare.