Skip to main content

Malware Protection in ISO 27799

$540.95
Adding to cart… The item has been added

Ensure your healthcare organisation’s malware protection framework meets the rigorous standards of ISO 27799 with this comprehensive self-assessment tool, designed specifically for the unique demands of clinical and hybrid IT environments. This programme delivers the depth of a multi-session technical consultancy, equipping information security leaders, risk managers, and IT governance teams with structured methodologies to align cybersecurity controls with international best practice.

Through two targeted modules, you’ll systematically evaluate and strengthen your organisation’s resilience against evolving cyber threats while maintaining clinical continuity and regulatory compliance.

  • Module 1 guides you through aligning malware controls with ISO 27799 control objectives, including extending protections to third-party hosted electronic health record (EHR) systems based on data residency agreements and legacy device constraints.
  • Determine appropriate control scope for medical devices with outdated operating systems, and map A.12.2.1 to existing technical safeguards, ensuring audit logs capture critical malware detection events.
  • Assess cloud email gateways against A.13.2.3 requirements and evaluate BYOD telehealth policies to balance staff privacy with patient data protection.
  • Module 2 focuses on proactive risk assessment, using STRIDE threat modelling to identify vulnerabilities in HL7 interfaces and PACS systems handling DICOM transfers.
  • Classify medical IoT assets—such as infusion pumps and patient monitors—by risk exposure and establish tiered mitigation strategies that support clinical uptime and incident response readiness.

This self-assessment enables you to identify control gaps, justify security investments, and demonstrate due diligence to regulators, insurers, and stakeholders. It’s an essential resource for healthcare organisations navigating complex compliance landscapes while defending critical systems and safeguarding patient information.

Take control of your cybersecurity posture—conduct a rigorous, standards-aligned evaluation today.