Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

An organization is migrating sensitive patient health information (PHI) to a new cloud-based electronic health record (EHR) system. The cybersecurity architect needs to ensure that the cloud environment adheres to HIPAA regulations, specifically regarding data encryption, access logging, and incident reporting. The architect also needs to demonstrate compliance to auditors. Which GRC technical strategy should be prioritized to provide continuous assurance and evidence of compliance for the cloud EHR system?

  1. AEstablishing a Security Information and Event Management (SIEM) system with custom HIPAA correlation rules.
  2. BDeploying a comprehensive Cloud Security Posture Management (CSPM) platform.
  3. CUtilizing a Web Application Firewall (WAF) to protect the EHR application.
  4. DImplementing a robust Data Loss Prevention (DLP) solution for all endpoints.
Show answer & explanation

Correct answer: B. Deploying a comprehensive Cloud Security Posture Management (CSPM) platform.

A CSPM platform continuously monitors the cloud environment for misconfigurations and compliance violations against frameworks like HIPAA, providing continuous assurance and audit evidence regarding encryption, access logging, and other controls.

Why the other options are wrong

  • A. While SIEM can collect logs and detect incidents related to HIPAA, it doesn't provide the continuous posture management and configuration assessment capabilities of a CSPM for the cloud infrastructure itself.
  • C. WAF protects web applications from common attacks but does not address the broader compliance requirements for the cloud environment hosting the EHR, such as data encryption at rest or access logging configurations.
  • D. DLP focuses on preventing data exfiltration, not on assessing the overall cloud infrastructure's adherence to compliance regulations like HIPAA.

Cloud Security Posture Management (CSPM)

CSPM continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation.

  • Identifies and remediates misconfigurations.
  • Ensures compliance with regulatory standards (e.g., HIPAA, GDPR).
  • Provides continuous visibility into cloud security posture.

Memory trick: CSPM 'Watches' the 'Cloud Hospital' for 'HIPAA Health'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions