Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy

A healthcare organization is preparing for an audit of its HIPAA compliance. The audit specifically focuses on ensuring that electronic protected health information (ePHI) is only accessible by authorized personnel who require it for their job functions. Which security principle is being evaluated?

  1. ANeed-to-Know
  2. BDue Diligence
  3. CSeparation of Duties
  4. DDue Care
Show answer & explanation

Correct answer: A. Need-to-Know

The 'Need-to-Know' principle dictates that access to sensitive information, such as ePHI, should only be granted to individuals who require it to perform their official duties.

Why the other options are wrong

  • B. Due Diligence is the proactive process of researching and understanding risks.
  • C. Separation of Duties prevents a single individual from controlling an entire critical process.
  • D. Due Care is the standard of care a reasonable person would exercise in a given situation.

Need-to-Know Principle

A security principle stipulating that individuals should only be granted access to the specific information or resources absolutely necessary for their job functions.

  • Reduces the risk of insider threats and accidental data exposure.
  • Often implemented through granular access controls.
  • Complements the principle of least privilege.

Memory trick: Least Privilege, Separation of Duties, Need-to-Know, Access Control Lists.

More Security Policies and Procedures questions