ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A healthcare provider is deploying a new electronic health record (EHR) system. The system must meet HIPAA regulations, which dictate strict rules for protecting patient data. The organization develops a document outlining mandatory actions and prohibitions for employees using the EHR, ensuring compliance and security. What type of security document is this?
- AGuideline
- BProcedure
- CPolicy
- DStandard
Show answer & explanationAnswer & explanation
Correct answer: C. Policy
A policy is a high-level statement from senior management that outlines the organization's security objectives and mandatory rules. It defines what must be done but not necessarily how, often driven by legal or regulatory requirements like HIPAA.
Why the other options are wrong
- A. Guidelines offer recommendations, not mandatory rules.
- B. Procedures provide detailed, step-by-step instructions on how to perform a task.
- D. Standards provide specific requirements for technologies or configurations, often supporting policies.
Policy (Security)
A high-level statement from senior management that outlines an organization's security objectives and mandatory rules for employees and systems.
- Mandatory and enforceable.
- Driven by legal, regulatory, or business needs.
- Answers the 'what' and 'why'.
Memory trick: Policies rule, standards define, procedures guide, guidelines advise.