Are the policies and standards that exist for each element of the requirement statement approved by management and communicated to the workforce? Do you have projects that require a HIPAA-Compliant authorization? Who do you inform? Is your workforce adequately educated about cyber-security threats and role in minimizing them? Are additional risk issues (unintended consequences) identified and described? Defining, designing, creating, and...