CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium

A healthcare organization is migrating its patient records system to a cloud-based platform. The project manager must ensure compliance with HIPAA regulations regarding protected health information (PHI). Which cloud characteristic is most critical for maintaining data privacy and regulatory adherence in this scenario?

  1. AShared responsibility model, defining security duties between provider and customer.
  2. BMeasured service, where resource usage is monitored, controlled, and reported.
  3. COn-demand self-service, allowing users to provision resources without human interaction.
  4. DBroad network access, enabling capabilities to be available over the network.
Show answer & explanation

Correct answer: A. Shared responsibility model, defining security duties between provider and customer.

The shared responsibility model explicitly defines which security and compliance tasks are handled by the cloud provider and which are handled by the customer. This is critical for HIPAA compliance, as the healthcare organization needs to know precisely where its responsibilities lie for protecting PHI in the cloud.

Why the other options are wrong

  • B. Measured service is for billing and resource optimization, not directly for data privacy compliance.
  • C. Self-service is a convenience but doesn't directly address data privacy or compliance requirements.
  • D. Broad network access is a fundamental cloud feature but doesn't inherently ensure compliance with specific regulations like HIPAA.

Cloud Shared Responsibility Model

A framework that outlines the security and compliance obligations of both the cloud service provider (CSP) and the cloud customer.

  • CSP is responsible for the 'security of the cloud' (infrastructure).
  • Customer is responsible for 'security in the cloud' (data, applications, configuration).
  • Crucial for understanding compliance boundaries.

Memory trick: Compliance in the Cloud: Shared Responsibility is Key.

More Basics of IT and Governance questions