- Get link
- X
- Other Apps
CYB 205 Infrastructure Administration
Q: Alex’s job requires him to see protected health information to ensure the proper treatment of patients. His access to their medical records does not provide access to patient addresses or billing information. What access control concept best describes this control?
A: Need to know
Explanation: Need to know is applied when subjects like Alex have access to only the data they need to accomplish their job. Need to know limits who has access to read, use, or modify data based on whether their job functions require them to do so.Answers D and B are incorrect. Separation or segregation of duties is used to limit fraud and abuse by having multiple employees perform parts of a task.Answer C is incorrect. Privilege creep happens when duties have changed and yet privileges that are no longer actually needed remain in effect for a given user.
- Get link
- X
- Other Apps
Comments
Post a Comment