Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy

A large healthcare provider is expanding its telehealth services, requiring secure communication and data exchange with remote patients and external specialists. The organization must comply with HIPAA regulations, which mandate strict data privacy and security controls. The cybersecurity architect needs to select a GRC technical strategy that ensures compliance while facilitating secure collaboration. Which strategy is MOST appropriate?

  1. ADeploying a comprehensive secure messaging and file sharing platform with audit capabilities.
  2. BUtilizing a network intrusion detection system (NIDS) to monitor perimeter traffic.
  3. CImplementing a robust patch management system for all endpoints.
  4. DEstablishing a bring-your-own-device (BYOD) policy with basic security guidelines.
Show answer & explanation

Correct answer: A. Deploying a comprehensive secure messaging and file sharing platform with audit capabilities.

A secure messaging and file sharing platform with audit capabilities directly addresses the need for secure communication and data exchange, which are critical for telehealth and HIPAA compliance. Audit capabilities ensure accountability and demonstrate compliance.

Why the other options are wrong

  • B. NIDS monitors for threats but does not provide a secure collaboration platform for sensitive data exchange.
  • C. Patch management is crucial for security but doesn't directly facilitate secure communication and data exchange for collaboration.
  • D. A BYOD policy, especially with only basic guidelines, introduces significant risks and is unlikely to meet strict HIPAA requirements for sensitive data handling.

Secure Collaboration Platforms

These platforms enable secure communication and data sharing among users, often incorporating encryption, access controls, and audit trails to meet compliance requirements.

  • Ensures confidentiality and integrity of shared data.
  • Provides granular access controls.
  • Often includes audit and logging features for compliance.

Memory trick: HIPAA needs secure chats, not just good defense.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions