312-50V10 · Question #570
Which of the following is a component of a risk assessment?
The correct answer is B. Administrative safeguards. A risk assessment includes administrative safeguards as a core component, covering the policies, procedures, and workforce practices that manage security risk at the organizational level.
Question
Which of the following is a component of a risk assessment?
Options
- APhysical security
- BAdministrative safeguards
- CDMZ
- DLogical interface
How the community answered
(50 responses)- A2% (1)
- B92% (46)
- C4% (2)
- D2% (1)
Why each option
A risk assessment includes administrative safeguards as a core component, covering the policies, procedures, and workforce practices that manage security risk at the organizational level.
Physical security is a category of safeguard that may be evaluated during a risk assessment, but it is not itself a component of the risk assessment process or methodology.
Administrative safeguards are a formally recognized component of risk assessment frameworks, encompassing management policies, workforce training, assigned responsibilities, and procedural controls. Under HIPAA Security Rule guidance and NIST standards, evaluating administrative safeguards is a direct requirement of a comprehensive risk assessment. They represent the human and process layer of security that must be analyzed alongside technical and physical controls.
A DMZ is a network architecture design element and is not a component or phase of a risk assessment framework.
A logical interface is a networking and system design concept and is not a recognized component within risk assessment methodology.
Concept tested: Risk assessment components - administrative safeguards
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
Topics
Community Discussion
No community discussion yet for this question.