Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A regulatory body has mandated that a healthcare organization must be able to demonstrate that only authorized medical professionals have accessed specific patient records. This requires logging every access attempt, indicating who accessed what, when, and from where. Which aspect of compliance is this requirement primarily addressing?
- AAuditability
- BData Privacy
- CData Sovereignty
- DData Minimization
Show answer & explanationAnswer & explanation
Correct answer: A. Auditability
Auditability refers to the ability to record, store, and retrieve records of events, such as access attempts, to verify compliance with policies and regulations. This directly addresses the need to demonstrate who accessed patient records.
Why the other options are wrong
- B. Data Privacy focuses on protecting personal data, but auditability is the *mechanism* for proving it.
- C. Data Sovereignty concerns where data is stored geographically, not who accessed it.
- D. Data Minimization involves collecting only necessary data, which is unrelated to logging access.
Auditability (Compliance)
The capability to record, store, and retrieve records of events and actions to verify compliance with policies, regulations, and security controls.
- Essential for demonstrating compliance to regulators.
- Requires robust logging and monitoring systems.
- Supports forensic analysis in case of a security incident.
Memory trick: Audits verify the A-ctions