Risk Management & Mitigation Flashcards
7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
Which risk treatment option involves transferring financial exposure to a third party, such as a cyber insurance policy?
Answer: Risk transference
Risk transference shifts financial liability to another party, commonly through cyber liability insurance or contractual indemnification clauses.
A healthcare organization conducts a Business Impact Analysis (BIA). What is the primary output of this process?
Answer: Recovery Time Objectives and critical business function rankings
A BIA identifies critical business functions and establishes Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) to prioritize recovery efforts.
Under HIPAA, a covered entity must report a breach to affected individuals within how many days of discovery?
Answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach.
Which framework provides a structured set of controls specifically designed for managing information security risk in healthcare organizations?
Answer: NIST SP 800-66
NIST SP 800-66 is an implementation guide for HIPAA Security Rule compliance, mapping NIST controls to healthcare security requirements.
A risk register entry shows a vulnerability with High likelihood and Low impact. What is the appropriate prioritization relative to a Low likelihood, High impact entry?
Answer: They typically receive similar priority; context determines precedence
Risk scoring multiplies likelihood by impact, so both scenarios can yield similar risk scores; organizational context and risk appetite determine final prioritization.
What does a Residual Risk represent in a risk management program?
Answer: The risk that remains after controls have been implemented
Residual risk is the remaining risk exposure after security controls and mitigation measures have been applied to inherent risk.
Which of the following best describes a Corrective control in health IT risk management?
Answer: Patch management that remediates a discovered software vulnerability
Corrective controls address and fix identified weaknesses or incidents after they occur, such as applying patches to remediate a known vulnerability.