CCSK · Question #12
CCM: A hypothetical company called: 'Health4Sure' is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among…
The correct answer is B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could. CCM, which is part of the CSA Governance, Risk and Compliance (GRC) Stack, is mapped to multiple industry standards, regulations and frameworks that enterprises must follow, including ISO 27001/27002, PCI DSS, HIPAA and COBIT.
Question
CCM: A hypothetical company called: 'Health4Sure' is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients. Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
Options
- AThe CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the
- BThe CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could
- CThe CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess
How the community answered
(35 responses)- A9% (3)
- B74% (26)
- C17% (6)
Explanation
CCM, which is part of the CSA Governance, Risk and Compliance (GRC) Stack, is mapped to multiple industry standards, regulations and frameworks that enterprises must follow, including ISO 27001/27002, PCI DSS, HIPAA and COBIT.
Topics
Community Discussion
No community discussion yet for this question.