Question

Difficulty: HardData Privacy and Compliance Regulations

A systems administrator for a global e-commerce enterprise is establishing security baseline controls for databases storing payment transaction history and European customer profiles. To maintain strict compliance with both PCI-DSS and GDPR regulations during routine data maintenance and archival, which of the following operational practices MUST the administrator implement? (Select TWO.)

  1. Apply industry-standard cryptographic encryption to payment cardholder data (CHD) and personal data both in transit across public networks and at rest in backup repositories.Answer
  2. Establish technical workflows to sanitize and permanently remove European Union customer records upon verified request under the right to be forgotten.Answer
  3. C
    Log full card verification value (CVV/CVC) codes alongside primary account numbers in unencrypted application audit files for post-transaction verification.
  4. D
    Retain all customer identity records indefinitely in active database tables to streamline open-ended legal discovery requests regardless of data subject opt-out notices.

Answer

The administrator must encrypt cardholder and personal data both at rest and in transit, and establish automated technical workflows to erase customer personal data upon valid GDPR right-to-be-forgotten requests.
The correct operational practices are applying strong cryptographic encryption to cardholder data and PII at rest and in transit, and setting up workflows to permanently erase EU customer data upon request under GDPR. PCI-DSS mandates encryption for cardholder data across storage and public network transmissions, while GDPR enforces technical data security (Article 32) and data erasure rights (Article 17).

Step-by-Step Solution

1
Analyze regulatory scope for PCI-DSS data protection requirements.
PCI-DSS requires safeguarding Cardholder Data (CHD) through robust encryption during storage and transit, while explicitly banning the retention of Sensitive Authentication Data (SAD/CVV) after authorization.
Protecting cardholder data limits exposure to credit card fraud and maintains compliance with payment processor frameworks.
2
Analyze regulatory scope for GDPR data subject rights and storage limitation.
GDPR requires pseudonymization/encryption of PII, adherence to storage minimization (retaining data no longer than necessary), and honoring data erasure (right to be forgotten) requests.
EU residents maintain legal ownership of their personal data rights under GDPR standards.
3
Select valid operational controls matching both regulations.
Implementing strong encryption for CHD/PII at rest and in transit, alongside automated data erasure procedures, fulfills both compliance directives.
These controls directly satisfy PCI-DSS encryption requirements and GDPR privacy rights.

Key Concept

Data Privacy and Compliance Regulations (PCI-DSS and GDPR Operational Controls)
Rate this question