nerdexam
Isaca

CGEIT · Question #47

Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?

The correct answer is D. Protecting personal health information. When transitioning from X-rays to digital images, the aspect best addressed by implementing information security policy and procedures is protecting personal health information.

Submitted by fatema_kw· Apr 18, 2026Risk Optimization

Question

Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?

Options

  • AEstablishing data retention procedures
  • BTraining technicians on acceptable use policy
  • CMinimizing the impact of hospital operation disruptions on patient care
  • DProtecting personal health information

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    14% (4)
  • D
    72% (21)

Why each option

When transitioning from X-rays to digital images, the aspect best addressed by implementing information security policy and procedures is protecting personal health information.

AEstablishing data retention procedures

Establishing data retention procedures is an important aspect of data governance, but the broader protection of PHI encompasses more than just retention, covering its entire lifecycle under security policies.

BTraining technicians on acceptable use policy

Training technicians on acceptable use policy is an implementation of security policy, not the policy itself addressing the aspect of protection.

CMinimizing the impact of hospital operation disruptions on patient care

Minimizing hospital operation disruptions relates more to business continuity and disaster recovery, which are separate from information security policies focused on data protection.

DProtecting personal health informationCorrect

Information security policies and procedures are specifically designed to establish rules and controls for safeguarding sensitive data, such as Personal Health Information (PHI). In the context of digital images, these policies are crucial for ensuring confidentiality, integrity, and availability of patient data in compliance with healthcare regulations like HIPAA, preventing unauthorized access, modification, or disclosure.

Concept tested: Information security policy for PHI

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/hipaa-compliance-overview

Topics

#Information security#Data protection#Personal health information#Digital transformation

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice