Exec Questions Flashcards

Risk Framework and Governance (7 cards)

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why is our governance score so low at 1.1?

A

Post-Change Healthcare acquisition integration challenges. Inconsistent policies across subsidiaries. New unified governance structure addresses this gap.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does 2.5 NIST score compare to industry peers?

A

Target 2.5 puts us above healthcare industry average of 2.2. Leading health systems typically score 2.3-2.7.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s the Board’s role in cybersecurity oversight?

A

Quarterly briefings, approval of investments over $5M, direct ownership of risk appetite statements. Enhanced with Mandiant advisory support.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do we ensure accountability across all subsidiaries?

A

Standardized cybersecurity charters, defined roles, clear escalation protocols. Executive Security Council ensures enterprise-wide alignment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens if we don’t meet the 2.5 target by FY2026?

A

Increased regulatory scrutiny, higher breach probability, potential business restrictions. Roadmap includes milestones to ensure we stay on track.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does this governance model prevent another Change Healthcare situation?

A

Unified visibility, standardized controls, mandatory compliance across all entities. No more subsidiary autonomy on critical security controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly