Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A healthcare organization is subject to strict regulations like HIPAA, which mandates the protection of electronic protected health information (ePHI). They need to ensure that their IT systems are configured to prevent unauthorized modification or destruction of patient records. Which security principle are they primarily focusing on?
- AIntegrity
- BAvailability
- CNon-repudiation
- DConfidentiality
Show answer & explanationAnswer & explanation
Correct answer: A. Integrity
Integrity ensures that data is accurate, complete, and protected from unauthorized modification or destruction. Preventing unauthorized modification or destruction of patient records directly aligns with the principle of integrity, which is critical for compliance with regulations like HIPAA.
Why the other options are wrong
- B. Availability ensures that authorized users can access information when needed, not its accuracy or prevention of modification.
- C. Non-repudiation ensures that a party cannot deny having performed an action, which is related but not the primary focus here.
- D. Confidentiality focuses on preventing unauthorized disclosure of information, not its modification.
Integrity
The security principle that ensures information is accurate, complete, and protected from unauthorized modification or destruction.
- Maintains data trustworthiness.
- Prevents unauthorized alteration.
- Crucial for regulatory compliance (e.g., HIPAA).
Memory trick: Integrity: 'Is this data the real deal, or has someone messed with it?'