A healthcare organization is updating its human risk management framework to reduce vulnerabilities associated with visual eavesdropping and unauthorized physical media in patient treatment areas. Which of the following administrative and security awareness measures should the security team implement to specifically address these human risk vectors? (Select TWO.)
- Enforce clear screen guidelines requiring staff to lock unattended workstations and install privacy filters on terminals in public view.Answer
- BDeploy network access control policies to automatically block physical USB storage devices across all endpoint operating systems.
- Deliver role-based training modules instructing clinical personnel on recognizing and reporting suspicious physical USB drives found in facility areas.Answer
- DMandate annual generic vishing simulations for clinical staff focused on phone-based financial wire transfer scams.
Answer
The organization should enforce clear screen guidelines with privacy filters and deliver role-based training focused on recognizing suspicious physical media.
Enforcing clear screen guidelines (mandating screen locks and privacy filters) directly counters physical shoulder surfing in high-traffic clinical areas. Providing role-based training on recognizing physical USB hazards equips personnel to counter baiting tactics effectively.
Step-by-Step Solution
Key Concept
Role-based security awareness programs and administrative controls for human risk management