- Certification
- HITRUST
- Modernized
- Corporate IT and endpoints
- Cyber risk reporting
- Executives and board
The problem
At Altais, a Blue Shield of California company, I was Head of Technology & Information Security from 2020 to 2022. This case covers two parts of that job: leading the effort to achieve HITRUST certification, and modernizing corporate IT and endpoint security.
HITRUST describes its CSF as bringing requirements from standards and regulations including ISO/IEC, NIST, HIPAA, PCI, and GDPR into a single, integrated control framework. That breadth is why I don't treat certification as a security project. The controls live in every function that runs a system, a laptop, or a process.
The approach
I led certification as a cross-functional effort. The way I run one: every control gets a named owner in the function that operates it, and security owns the framework, the evidence standard, and the schedule.
The IT modernization covered network design, workstation lifecycle, asset management, and helpdesk. I treat that as part of the same program. You can't show a control on endpoints you can't count, and the workstation lifecycle is where endpoint controls get applied or skipped.
I also presented to executive leadership and the board on cyber risk. I've written up how I report risk to people who don't speak security.
The outcome
Altais achieved HITRUST certification, and corporate IT and endpoint security were modernized from network design through helpdesk. Keeping a certification true is ongoing work after the assessor leaves, the case I make in The Audit Passed in March.