Choosing controls should start with requirements, not products. A system's security requirements come from its data classification, business function, laws and contracts, risk assessment and the organization's policies. Once you know what the system must achieve, for example 'only authenticated clinicians can view patient records, and every access is logged', you select controls that meet those requirements and later verify that they do. Starting from a favorite product instead often leaves real requirements unmet while spending money on features nobody needed.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.