A regional hospital network is updating its data governance framework prior to deploying a new cloud-based electronic health records system. To align with data privacy regulations, the security steering committee must clearly separate administrative authority from technical execution responsibilities. Which of the following responsibilities is primarily assigned to the data owner?
- Determining the appropriate security classification label and defining access policies for patient electronic health recordsAnswer
- BImplementing nightly encrypted database backups and configuring storage array redundancy
- CConfiguring network access control lists (ACLs) to verify user identity before granting session access
- DDeploying an intrusion prevention system (IPS) to detect and block unauthorized database query patterns
Answer
Determining the appropriate security classification label and defining access policies for patient electronic health records
The correct answer identifies the primary authority of the data owner: setting classification levels, defining policy parameters, and granting access permissions for data assets. The data owner is ultimate responsible for the business value and security requirements of the data.
Step-by-Step Solution
Key Concept
Data Owner vs. Data Custodian Responsibilities
Estimated Time:1m 30s