CHI Risk Management & Mitigation 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring financial exposure to a third party, such as a cyber insurance policy?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts financial liability to another party, commonly through cyber liability insurance or contractual indemnification clauses.
Question 2: A healthcare organization conducts a Business Impact Analysis (BIA). What is the primary output of this process?
- A list of all system vulnerabilities
- Recovery Time Objectives and critical business function rankings (Correct answer)
- A completed risk register
- An updated incident response plan
Correct answer: Recovery Time Objectives and critical business function rankings
A BIA identifies critical business functions and establishes Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) to prioritize recovery efforts.
Question 3: Under HIPAA, a covered entity must report a breach to affected individuals within how many days of discovery?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach.
Question 4: Which framework provides a structured set of controls specifically designed for managing information security risk in healthcare organizations?
- COBIT
- NIST SP 800-66 (Correct answer)
- ISO 31000
- PMBOK
Correct answer: NIST SP 800-66
NIST SP 800-66 is an implementation guide for HIPAA Security Rule compliance, mapping NIST controls to healthcare security requirements.
Question 5: A risk register entry shows a vulnerability with High likelihood and Low impact. What is the appropriate prioritization relative to a Low likelihood, High impact entry?
- Always prioritize the High likelihood entry
- Always prioritize the High impact entry
- They typically receive similar priority; context determines precedence (Correct answer)
- The High likelihood entry is always deprioritized
Correct answer: They typically receive similar priority; context determines precedence
Risk scoring multiplies likelihood by impact, so both scenarios can yield similar risk scores; organizational context and risk appetite determine final prioritization.
Question 6: What does a Residual Risk represent in a risk management program?
- The risk level before any controls are applied
- The risk that remains after controls have been implemented (Correct answer)
- The maximum tolerable risk threshold
- The risk transferred to a third-party vendor
Correct answer: The risk that remains after controls have been implemented
Residual risk is the remaining risk exposure after security controls and mitigation measures have been applied to inherent risk.
Question 7: Which of the following best describes a Corrective control in health IT risk management?
- Locks that prevent unauthorized physical access to server rooms
- Audit logs that record user activity
- Patch management that remediates a discovered software vulnerability (Correct answer)
- Security awareness training for staff
Correct answer: Patch management that remediates a discovered software vulnerability
Corrective controls address and fix identified weaknesses or incidents after they occur, such as applying patches to remediate a known vulnerability.
Which risk treatment option involves transferring financial exposure to a third party, such as a cyber insurance policy?