Stock Abbreviation : Topsec      Stock Code : 002212
7*24 hour service: 400-777-0777

The cybersecurity operation project for a tertiary first-class hospital under the supervision of the National Health Commission of People’s Republic of China (NHC)

Proactive defense | Fit customers’ situation | Gradient cybersecurity operation



Background

In recent years, the digitalization process of the medical industry has been accelerating. However, the industry is facing increasingly serious information security risks contrast to the rapidly improving medical service quality. Therefore, the traditional static security protection means of relying on security devices can no longer cope with the current severe cybersecurity situation. To ensure the security of network systems and core network applications, the customer urgently need a third-party professional security team to assist in establishing a systematic and continuous cybersecurity operation system, improving threat perception, event disposal, monitoring and warning capabilities to proactively identify vulnerabilities and risks, and ensure a closed loop of hospital information security.

Activity & Announcement
Solution architecture

Based on customer needs and the hospital’s current cybersecurity situation, Topsec security service experts design a security operation model based on security capability maturity. With assets as the core, evaluation as the means and threat control as the purpose, Topsec formulates an overall security planning scheme and assists customers in improving four major capabilities of asset systematic management, detection and protection, threat analysis and response, and defense strategy optimization in different gradients to gradually enhance its security operation capability framework.
Gradient I: basic operation stage (completed)

Topsec help the customer initially establish security operation mechanism by manual operation with tools assisted, and standardize basic network security management process simultaneously to provide fundamental support for further operation work.

Gradient II: workflow operation stage (under construction)

After the target of basic operation stage is met, workflow operation capability construction is carried out. In this stage, Topsec security experts assist customers to conduct the four major security capabilities, gradually integrate various processes and personnel capabilities into the security operation platform, release personnel energy to focus more on improving the operation level, continuously enhance the automation of operation work, and establish the prototype of cybersecurity operation system.

Gradient III: automatic operation stage (under planning, to be launched)

After the workflow security operation capability has been improved to a certain level, Topsec will further assist the customer to deepen the integration between security operation workflow and platform, and the engineering of personnel capability by taking advantage of AI and big data analysis technology and realize automatic identification, automatic research and judgment, automatic disposal and continuous improvement of the platform.

Value to customer
Workflow-oriented assets management capability

Relying on the existing platform and tools, Topsec helps the customer realizes flow-based asset automation discovery, complete the construction of business logic-based configuration database, so that its asset management capability can be upgraded from manual procedure to standardized management and semi-automated mapping.

Semi-automatic detection and threat analysis capability

Based on the daily security event monitoring mechanism and the analysis results, Topsec helps customers establish security detection strategies and security protection models that fit their business features, thus achieving the automatic execution of vulnerability detection and automatically distributing the analysis results to the corresponding person in charge for reinforcement.

Update and improvement of cybersecurity operation capability

During the operation, Topsec helps customers continuously improve the active and passive defense system, form the all-weather, all-time security protection and monitoring system, and constantly improve the hospital network information security protection capability to defend and respond to various network security events.