Ontario’s new advisory panel on improving cybersecurity maturity of municipalities, school boards, hospitals and other provincially-funded agencies has agreed as a first step that its final report will encourage organizations to take a risk-based approach to their efforts. However, how the panel will recommend the government put teeth into that has yet to be determined. In an interview Wednesday shortly after the panel’s first meeting, chairman Robert Wong — executive vice-president and chief information officer of Toronto Hydro — said a risk-based approach is what the Ontario Energy Board (OEB) mandated the 65 local electric distribution companies like Toronto Hydro to do starting in 2018. Each company has to fill out an annual Readiness Report on its cyber and privacy risk status. The self-assessment uses the Ontario Cybersecurity Framework’s security controls. It’s a framework similar to the U.S. National Institute of Standards and Technology’s (NIST) cyber framework for measuri...
Providing IT professionals with a unique blend of original content.