正解:B
The most important consideration during the requirements gathering phase of AI development in a healthcare organization is data privacy concerns (B). From a CISM governance and risk management perspective, healthcare organizations handle highly sensitive personal and regulated data, such as protected health information (PHI), which is subject to strict privacy, confidentiality, and regulatory requirements. During requirements gathering, it is critical to ensure that legal, regulatory, and ethical obligations related to data use, retention, consent, access controls, and cross-border processing are fully understood and incorporated into system requirements.
Algorithm selection (A), computational resources (C), and data labeling efficiencies (D) are important technical and operational considerations, but they are secondary and should be addressed only after privacy requirements are clearly defined. CISM emphasizes that security and privacy must be built in by design, not retrofitted later in development. Failure to address privacy requirements early can result in regulatory noncompliance, reputational damage, and unacceptable risk exposure.
In healthcare, governance-driven requirements-especially privacy, data minimization, and lawful processing-must guide AI system design to ensure alignment with organizational risk appetite and compliance obligations.
References:
ISACA CISM Review Manual, Information Security Governance - privacy, regulatory compliance, and emerging technology risk ISACA CISM Exam Content Outline, Domain 2: Information Security Governance