ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A healthcare provider is decommissioning an old server that stored millions of patient records. Due to strict HIPAA regulations, they must ensure that all data on the server is permanently unrecoverable before the server leaves their premises. Which security operation dictates the specific methods and procedures required to achieve this goal?

  1. ASecure Disposal
  2. BData Handling
  3. CData Retention
  4. DLog Management
Show answer & explanation

Correct answer: A. Secure Disposal

Secure disposal specifically deals with the permanent destruction or sanitization of data and hardware to prevent unauthorized recovery, which is critical for compliance with regulations like HIPAA when decommissioning systems with sensitive information.

Why the other options are wrong

  • B. Data handling concerns how data is processed and stored, not its final destruction.
  • C. Data retention defines how long data is kept, not how it's destroyed.
  • D. Log management collects event data, unrelated to data destruction.

Secure Disposal

The process of permanently removing data from storage media and/or destroying the media itself to prevent unauthorized recovery and ensure compliance with privacy regulations.

  • Methods include degaussing, shredding, and overwriting.
  • Crucial for protecting sensitive information.
  • Ensures compliance with data privacy laws.

Memory trick: Disposal Destroys Data Definitively.

More Security Operations questions