Section 13.117 Performing an External Assessment Flashcards

Objective 5.5 Explain types and purposes of audits and assessments

1
Q

External Assessment

A

Part of maintaining a robust security posture and ensuring compliance

Checklist and procedures vary depending on Governance, Risk and Compliane practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

EXAMPLE: Sample checklist used for a HIPAA external assessment

HIPPA Audit Checklist

A

Purpose is to validate compliance with specific regulations and minimise cybersecurity risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Preparing for a HIPAA External Assessment

A

■ Examiners provide a checklist of questions that organizations must answer

■ Questions are answered as either “yes” or “no”

■ Evidence files, such as documents or links, must be provided to demonstrate
compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Sample Checklist

A

■ Questions cover various aspects like general information, policies, procedures, and employee training

■ Organizations must provide evidence files as proof of compliance

■ External assessments aim to provide a quick overview of the organization’s
current risk posture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly