Resource Library
Solution BriefsComplianceVisibilityFebruary 15, 2024

Meet Data Security and Protection Toolkit (DSPT) Requirements with ORDR

SOLUTION BRIEF

Overview

Organisations that work with or have access to data and systems of the National Health System (NHS) are required to meet the Data Security Protection Toolkit (DSPT) requirements to maintain a baseline of security and privacy for sensitive information in the NHS digital supply chain.

Because cybersecurity is a dynamic environment, with evolving threats demanding evolving strategies for countering those threats, the DSPT regularly updates its guidelines and recommendations. That makes it imperative to maintain a cybersecurity program that is state-of-the-art to achieve and maintain compliance. It is also important to invest in cybersecurity tools that are engineered to automate the hard work.

ORDR Connected Device Security

ORDR enables a "Whole Hospital" approach to connected device security built on the philosophy of SEE, KNOW, and SECURE to help organisations close security gaps endemic to connected device deployments which are increasingly common in today’s healthcare IT environments.

Secure the "Whole Hospital" for NHS Trust

The ORDR solution helps the NHS Trust exceed the standards established by the Department of Health and Social Care as articulated under DSPT v4.

Key ORDR Capabilities

SEE

KNOW

SECURE

Every asset and connection

All risks and behaviors

Every thing

  • Discover and profile every device
  • Map every network connection and flow
  • Understand device utilization
  • Identify devices with vulnerabilities
  • Identify potential exploits
  • Identify anomalous behavior
  • Proactive Zero Trust policies on NAC, FW, switches
  • Reactive policies for incident response
  • Retrospective analysis for new IoCs

Asset Visibility — Automatically discover, accurately classify, and collect high fidelity details of every device on the network including newly connected devices.

Behavioural Profiling — Establish a baseline of normal communications for every device to identify active threats including zero-day attacks.

Asset Inventory — Integrate with CMMS and CMDB products to ensure device inventories are always up to date with accurate details.

Threat Response — Improve threat response and with dynamically created policy enforced with existing security and network infrastructure.

Vulnerabilities and Risk — Identify devices with vulnerabilities and risk such as outdated operating systems, unpatched or unauthorized software, PHI, recalls, risky communications, and anomalous behaviour.

Device Risk Rating — Automatically calculate real-time risk ratings per device by combining vulnerabilities, risk, and customizable parameters to help prioritize remediation and mitigation efforts.

Ecosystem Integrations — 80+ integrations with security, network, and IT products to enrich device insights, enable existing workflows, improve security efforts, and accelerate Zero Trust initiatives.

Vulnerability Management — Robust vulnerability management and mitigation capabilities including integration with existing IT tools, workflows, and network and security infrastructure to help teams efficiently manage risk.

Accelerate Zero Trust — Automate the creation of Zero Trust policy such as NAC or segmentation to reduce the attack surface and improve security.

Compliance — Generate custom reports that map to the DSPT submission and a solution that is SOC 2 Type 2 certified, encrypts data at rest and in motion, does not collect PHI or PII data, and meets GDPR data privacy requirements by ensuring that all data collected remains in the United Kingdom.

Frequently asked questions
How does ORDR help healthcare organizations meet NHS DSPT v4 requirements?
ORDR's platform maps discovered IoT and medical devices directly to specific DSPT v4 security mandates, automatically validating behavioral profiles against compliance standards. This enables healthcare providers to generate audit-ready evidence linking their device inventory to toolkit requirements without manual mapping.
Can ORDR automatically validate devices against DSPT compliance standards?
Yes. ORDR uses behavioral profiling to automatically validate connected devices against DSPT compliance standards, eliminating manual validation work. The platform generates compliance evidence that demonstrates security controls are in place and functioning as required.
What kind of audit evidence does ORDR provide for DSPT compliance?
ORDR provides audit-ready evidence that links your complete device inventory to specific DSPT v4 security requirements, including asset discovery findings and behavioral validation results. This documentation accelerates compliance validation and reduces the burden on healthcare IT and security teams during assessments.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →