ISC2 Certified in Cybersecurity (CC)Security OperationsEasy

A small medical clinic is implementing a new electronic health record (EHR) system. They need to ensure that patient data, which is highly sensitive, is protected from unauthorized access during all stages of its lifecycle, from creation to destruction. Which security operation is primarily concerned with defining and enforcing policies for how this sensitive data is handled?

  1. AData Classification
  2. BAsset Management
  3. CSecurity Monitoring
  4. DVulnerability Scanning
Show answer & explanation

Correct answer: A. Data Classification

Data classification involves categorizing data based on its sensitivity and impact if compromised. This process is crucial for determining the appropriate security controls and handling procedures for sensitive information like patient data, ensuring its protection throughout its lifecycle.

Why the other options are wrong

  • B. Asset management focuses on tracking and managing IT assets, not specifically on data handling policies.
  • C. Security monitoring observes systems for security events, it doesn't establish data handling rules.
  • D. Vulnerability scanning identifies weaknesses in systems but doesn't define data handling policies.

Data Classification

The process of categorizing data based on its sensitivity and value to an organization, which then dictates the security controls applied to it.

  • Helps determine appropriate security controls.
  • Often involves labels like 'Public', 'Internal', 'Confidential', 'Restricted'.
  • Crucial for compliance and risk management.

Memory trick: Classify Data to Clarify Controls.

More Security Operations questions