#298 Jason Taule - CISO at HITRUST

Episode 298 ·

Today we are talking to Jason Taule, the CISO at HITRUST.  And we discuss the way a CISO should operate within the C-Suite, why we should be thinking about risk instead of security, and how to create a culture that is mindful of risk management.

All of this, right here, right now, on the Modern CTO Podcast!

Check them out at HITRUSTAlliance.net!

About Jason:

Jason Taule is a 30+ year information assurance and cybersecurity veteran who has worked in both the intelligence community and commercial sectors, first consulting to federal agencies and then serving as inside CISO and CPO both within the government and at-large systems integrators like General Dynamics and CSC.

Mr. Taule helped build the original DARPA CERT, helped develop the first computer security programs at the VA and NASA, and revised the Risk Assessment Methodology still used throughout DHHS. Mr. Taule helped author the Maryland Data Privacy Law, led a multi-million dollar global cybersecurity practice for a large international consulting firm, ran the team responsible for HIPAA complaint investigations for OCR for three years, and for the last 20 years has been a luminary in the U.S. Health IT sector helping hundreds of systems earn their accreditations and avoid compromise.

Mr. Taule currently serves as HITRUST Vice President of Standards and Chief Information Security Officer (CISO). In this capacity, he oversees the ongoing development and evolution of the HITRUST CSF security and privacy controls framework to ensure its continued relevancy and sufficiency. This includes abroad range of HITRUST risk management framework support functions such as requirements integration, control specification, and the development of standards that organizations can use to develop their own information protection and compliance programs and provide assurances to customers, trading partners, and other third parties. Additionally, Mr. Taule oversees HITRUST’s internal information assurance efforts to ensure that the organization continues to earn and keep the confidence of customers and third parties who have entrusted HITRUST with the safekeeping of their data.

Mr. Taule holds a Master of Science in Information Technology Management from Johns Hopkins University and a Bachelor of Business Administration from the College of William and Mary. Mr. Taule has earned numerous industry and professional certifications, is a graduate of the FBI Citizen’sAcademy, is member of the Homeland Security Preparation and ResponseTeam, serves on the Board of the Loyola Sellinger School of Business and theHoward County Economic Development Authority Technology Council, and isa founding member of and National Advisor to the CISO Executive Network.Mr. Taule sits on the DHHS/CMS Information Security and Privacy Workgroup, the FBI Cyber Health Work Group, the U.S. Health IT Standards Committee’s Transport and Security Workgroup and is a White House invitee to theSecurity Policy Roundtable for the President’s Precision Medicine Initiative.

About HITRUST:

Since it was founded in 2007, HITRUST has championed programs that safeguard sensitive information and manage information risk for global organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security and risk management leaders from the public and private sectors, HITRUST develops, maintains and provides broad access to its widely-adopted common risk and compliance management frameworks, related assessment and assurance methodologies.

HITRUST understands the challenges of assembling and maintaining the many and varied programs needed to manage information risk and compliance. The HITRUST Approach provides organizations a comprehensive information risk management and compliance program to provide an integrated approach that ensures all programs are aligned, maintained and comprehensive to support an organization’s information risk management and compliance objectives.