nerdexam
Isaca

CISA · Question #649

An IS auditor is reviewing an AI system utilized by a healthcare organization for patient pre- diagnosis. Which of the following would pose the GREATEST concern?

The correct answer is D. Lack of discretionary access control. Lack of discretionary access control (D) is the greatest concern because patient health information (PHI) is among the most sensitive data a system can handle - without access controls governing who can view or manipulate it, the AI system exposes the organization to unauthorized

Submitted by helene.fr· Apr 18, 2026Protection of Information Assets

Question

An IS auditor is reviewing an AI system utilized by a healthcare organization for patient pre- diagnosis. Which of the following would pose the GREATEST concern?

Options

  • AOutdated AI knowledge base
  • BOutdated AI system refinement process
  • CLack of an emergency change log
  • DLack of discretionary access control

How the community answered

(39 responses)
  • A
    23% (9)
  • B
    13% (5)
  • C
    5% (2)
  • D
    59% (23)

Explanation

Lack of discretionary access control (D) is the greatest concern because patient health information (PHI) is among the most sensitive data a system can handle - without access controls governing who can view or manipulate it, the AI system exposes the organization to unauthorized data access, HIPAA violations, and patient harm. This is a foundational security failure: no compensating control can substitute for it, and an IS auditor would flag it as an immediate, critical risk.

The distractors are real concerns but lower severity: an outdated knowledge base (A) affects diagnostic accuracy but can be mitigated by physician oversight; an outdated refinement process (B) impacts model performance over time but is an operational gap, not a security breach; and lack of an emergency change log (C) weakens auditability and forensics but doesn't directly expose PHI to unauthorized parties.

Memory tip: In healthcare IT audits, think "Access Before Accuracy" - controlling who can reach the data always outranks concerns about how well the system performs, because a data breach is irreversible harm, while a process gap can be patched.

Topics

#Access Control#AI System Security#Information Security#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice