CISSP Practice Question: In a mid-sized healthcare organization, which is MOST likely to be prioritized…
Correct Answer: A. Compliance with HIPAA
Explanation (CISSP Manager Logic):
Regulatory requirements establish the non-negotiable baseline for data governance in specialized industries like healthcare. Prioritizing HIPAA ensures the classification scheme addresses legal liabilities and protects the organization's most critical asset: patient privacy.
By implementing this solution, you:
- Mitigate legal and financial risks associated with regulatory non-compliance.
- Establish a standardized framework for identifying and protecting sensitive PHI.
- Align security investments with the organization’s primary risk profile.
While the other options are relevant, they fall short because:
- B: Maximizing accessibility often conflicts with the principle of least privilege and increases breach risks.
- C: Cost-cutting can lead to inadequate controls, resulting in higher long-term expenses from fines.
- D: Encryption is a specific technical control, whereas classification is a broader governance requirement.
Think like a manager:
Always prioritize legal and regulatory obligations as they define the organization's minimum security baseline. Effective asset security starts with understanding the compliance landscape to drive strategic resource allocation.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial