โ† All CRM Flashcard Decks

Risk Management & Security Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Security flashcards as text
  1. Which standard provides a globally recognized framework for establishing, implementing, and maintaining an information security management system (ISMS)?

    Answer: ISO 27001

    ISO 27001 specifies requirements for an ISMS, covering risk assessment, controls, and continuous improvement for information security.

  2. An employee intentionally leaks confidential records to a competitor. This scenario is an example of which type of threat?

    Answer: Malicious insider threat

    A malicious insider threat involves an authorized employee deliberately misusing access to harm the organization by disclosing confidential records.

  3. When records are transferred between organizations as part of a merger, which security measure is most important to implement immediately?

    Answer: Reclassifying and reviewing access rights to transferred records

    Reclassifying records and reviewing access rights ensures that only authorized personnel in the new organization can access sensitive transferred records.

  4. What is the primary purpose of a records security audit trail?

    Answer: To provide a chronological record of who accessed or modified records and when

    An audit trail logs all access and modification activity on records, enabling accountability, forensic investigation, and compliance verification.

  5. Under HIPAA Security Rule requirements, covered entities must implement which type of control to protect electronic protected health information (ePHI)?

    Answer: Administrative, physical, and technical safeguards in combination

    The HIPAA Security Rule mandates a three-part framework of administrative, physical, and technical safeguards to protect ePHI comprehensively.

  6. A records manager implements a clean desk policy. Which risk does this policy primarily address?

    Answer: Risk of unauthorized viewing or theft of physical records left unattended

    A clean desk policy reduces the risk that sensitive paper records or credentials left on desks could be seen or taken by unauthorized individuals.

  7. Which term describes the comprehensive process of identifying, analyzing, evaluating, and treating risks to an organization's records throughout their lifecycle?

    Answer: Records risk management

    Records risk management encompasses the full cycle of identifying and treating risks to records from creation through final disposition.