CRISC Certified in Risk and Information Systems ControlGovernanceHard

A healthcare provider is migrating its patient records to a cloud-based electronic health record (EHR) system. This involves sharing sensitive patient data with a third-party vendor. To ensure effective governance, which of the following is the MOST crucial initial step in managing the risks associated with this third-party relationship?

  1. ANegotiating a service level agreement (SLA) that includes uptime guarantees and performance metrics.
  2. BConducting a comprehensive security audit of the cloud vendor's infrastructure.
  3. CImplementing a robust data encryption strategy for all patient data in transit and at rest.
  4. DEstablishing clear roles and responsibilities for data ownership and stewardship between the provider and vendor.
Show answer & explanation

Correct answer: D. Establishing clear roles and responsibilities for data ownership and stewardship between the provider and vendor.

Before engaging with a third-party vendor for sensitive data, establishing clear roles and responsibilities for data ownership and stewardship is paramount. This foundational step defines who is accountable for what aspects of data protection, ensuring proper governance and avoiding ambiguity in risk management.

Why the other options are wrong

  • A. An SLA focuses on service delivery and performance, not directly on the fundamental governance of data ownership and stewardship.
  • B. A security audit is important but comes after defining who is responsible for data security in the first place.
  • C. Encryption is a technical control for data protection; it's implemented after establishing governance and responsibilities.

Organizational Governance

The system by which an organization is directed and controlled. It encompasses the framework of authority, accountability, and oversight.

  • Ensures objectives are achieved.
  • Provides oversight for risk management.
  • Includes roles, policies, and processes.

Memory trick: First, define who owns the data, then audit the cloud.

More Governance questions