CISSP Practice Question: As the CISO of a mid-sized healthcare organization facing strict HIPAA regulations,…
Correct Answer: B. Conduct a comprehensive risk assessment
Explanation (CISSP Manager Logic):
A risk assessment is the foundational step for aligning security with business objectives and regulatory requirements like HIPAA. It provides the necessary data to prioritize resources, justify expenditures to stakeholders, and ensure security measures support rather than hinder the new telehealth service.
By conducting a risk assessment, you:
- Identify specific threats and vulnerabilities unique to the telehealth environment.
- Quantify potential impacts to ensure informed decision-making by legal and finance.
- Establish a baseline for selecting cost-effective, compliant security controls.
While the other options are relevant, they fall short because:
- A: Encryption is a specific technical control that should be implemented only after the assessment determines its scope.
- C: Training is essential but must be tailored to the specific risks and workflows identified during the assessment.
- D: Deploying technology without a risk-based justification leads to budget mismanagement and potential operational friction.
Think like a manager:
Never commit resources or select technical solutions before identifying the risks. Security must be a business enabler driven by data-backed strategy rather than technical impulse.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial