ISO 27799:2016 - Health Informatics Information Security Manager Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A healthcare organization\'s information security manager is reviewing the existing policy for the retention and secure destruction of electronic health records (EHRs). The organization operates under a jurisdiction that has recently enacted the \"Digital Health Act of 2035,\" which stipulates a mandatory minimum retention period of 15 years for all patient EHRs, with allowances for extended retention based on specific medical conditions or approved research protocols, and mandates a verifiable secure destruction process upon expiry of the retention period. The current organizational policy dictates the destruction of EHRs after 10 years, without specific provisions for extensions or verifiable destruction methods. What is the most appropriate immediate action for the information security manager to take to ensure compliance with the new legislation and the principles of ISO 27799:2016?

Initiate a comprehensive review and update of the organization's information retention and destruction policy to align with the "Digital Health Act of 2035" and ISO 27799:2016 requirements, including provisions for extended retention and secure destruction.
Document the discrepancy between the current policy and the new legislation as a risk, and await further guidance from the legal department before making any changes.
Implement a new policy that extends the retention period to 15 years but omits the specific provisions for extended retention based on medical conditions or research, and does not detail verifiable destruction methods.
Conduct an audit of all current EHRs to identify those that have exceeded the 10-year retention period but are still within the new 15-year mandate, and flag them for potential future review.

About the ISO 27799:2016 - Health Informatics Information Security Manager Certification

These free practice questions are designed to help you assess your readiness for the ISO 27799:2016 - Health Informatics Information Security Manager exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.