CAS-002 · Question #191
A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has…
The correct answer is B. Compliance may not be supported by all smartphones. C. Equipment loss, theft, and data leakage. F. Not all smartphones natively support encryption. Allowing personal smartphones to access health data raises compliance gaps, data protection risks, and encryption inconsistencies that the ISO must prioritize.
Question
A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has received a technical document from the security administrator explaining that the current email system is capable of enforcing security policies to personal smartphones, including screen lockout and mandatory PINs. Additionally, the system is able to remotely wipe a phone if reported lost or stolen. Which of the following should the Information Security Officer be MOST concerned with based on this scenario? (Select THREE).
Options
- AThe email system may become unavailable due to overload.
- BCompliance may not be supported by all smartphones.
- CEquipment loss, theft, and data leakage.
- DSmartphone radios can interfere with health equipment.
- EData usage cost could significantly increase.
- FNot all smartphones natively support encryption.
- GSmartphones may be used as rogue access points.
How the community answered
(36 responses)- A6% (2)
- B83% (30)
- E8% (3)
- G3% (1)
Why each option
Allowing personal smartphones to access health data raises compliance gaps, data protection risks, and encryption inconsistencies that the ISO must prioritize.
Email system overload is an operational availability concern, not an information security issue, and is lower priority than data confidentiality risks in a healthcare context.
Personal smartphones vary widely in OS and hardware capabilities, meaning some devices will not support the MDM security policies (PIN enforcement, screen lock, remote wipe) described, creating uncontrollable compliance gaps.
Health data on personal devices significantly increases the risk of data leakage and makes sensitive information harder to control if a device is lost or stolen, even with remote wipe capabilities.
Radio frequency interference is a physical patient safety concern regulated separately from information security and is not within the ISO's information security purview.
Increased data usage costs are a financial and operational concern, not an information security risk.
Not all smartphone platforms and older devices natively support data-at-rest encryption, leaving health data potentially unprotected even when the email system enforces other policies.
While rogue access points are a valid security concern, they are not directly tied to the email access scenario described and are less probable than the selected concerns.
Concept tested: BYOD security risks in regulated healthcare environments
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.