Risk Management & Mitigation Flashcards
7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
Which metric represents the estimated monetary loss from a single successful threat event?
Answer: Single Loss Expectancy (SLE)
SLE is calculated as Asset Value × Exposure Factor and represents the expected loss from one occurrence of a specific threat.
During a tabletop exercise, a health system simulates a ransomware attack on its clinical systems. What is the primary goal of this exercise?
Answer: To evaluate staff and leadership response without disrupting live systems
Tabletop exercises are discussion-based scenarios designed to test decision-making and response coordination without impacting production environments.
A Business Associate Agreement (BAA) is best described as:
Answer: A legal contract requiring a vendor with PHI access to comply with applicable HIPAA safeguards
A BAA is a required contractual agreement that obligates business associates to appropriately safeguard PHI and report breaches, but does not transfer all liability from the covered entity.
Which of the following is the MOST effective control to mitigate the risk of insider threats to PHI?
Answer: Implementing role-based access control with least privilege
Role-based access control with least privilege limits users to only the PHI they need for their job, directly reducing the scope of potential insider misuse.
An organization's Risk Appetite Statement indicates it will tolerate Low risks without further action. A newly identified risk is scored as Medium. What is the required next step?
Answer: Escalate to senior leadership and select a risk treatment option
When identified risk exceeds the defined risk appetite, it must be escalated and a treatment option (mitigate, transfer, avoid, or formally accept with rationale) must be selected.
What is the key difference between a vulnerability and a threat in health IT risk terminology?
Answer: A threat is an actor or event that could exploit a weakness; a vulnerability is the weakness itself
In risk terminology, a threat is a potential cause of harm (e.g., a hacker or natural disaster), while a vulnerability is a gap or weakness that a threat could exploit.
Which NIST document provides the core framework for cybersecurity risk management using five functions: Identify, Protect, Detect, Respond, Recover?
Answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) organizes cybersecurity activities into five core functions — Identify, Protect, Detect, Respond, and Recover — to manage and reduce risk.