Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

Match each regulatory compliance framework or legal mandate on the left with its primary data governance scope and organizational requirement on the right.

  • Sarbanes-Oxley Act (SOX)Regulates internal accounting controls and corporate financial reporting transparency for publicly traded organizations.
  • Health Insurance Portability and Accountability Act (HIPAA)Mandates administrative, physical, and technical safeguards for Electronic Protected Health Information (ePHI) held by covered entities.
  • Payment Card Industry Data Security Standard (PCI-DSS)Requires contractual technical and operational controls for entities that store, process, or transmit Cardholder Data (CHD).
  • General Data Protection Regulation (GDPR)Grants strict personal privacy rights—such as the right to erasure—and mandates data protection compliance for processing personal data of EU residents.

Answer

Sarbanes-Oxley Act (SOX) matches internal financial and accounting controls; HIPAA matches administrative, physical, and technical safeguards for ePHI; PCI-DSS matches operational security controls for processing cardholder data (CHD); GDPR matches data privacy rights and regulations concerning the processing of personal data.
Each mandate addresses distinct legal and regulatory objectives: SOX ensures financial statement integrity; HIPAA secures protected health information (ePHI); PCI-DSS safeguards credit card numbers and authentication data (CHD); GDPR safeguards individual data privacy rights across the European Union.

Step-by-Step Solution

1
Identify the primary domain governed by Sarbanes-Oxley Act (SOX).
SOX focuses on corporate accounting and financial reporting transparency.
SOX was passed to safeguard investors from corporate financial fraud.
2
Identify the protected data class for HIPAA.
HIPAA protects Electronic Protected Health Information (ePHI).
HIPAA mandates specific security controls for healthcare organizations and business associates handling health records.
3
Determine the governing scope of PCI-DSS.
PCI-DSS governs credit card holder data (CHD).
It is a private industry standard enforced by credit card brands to secure merchant processing environments.
4
Map GDPR to its data governance framework.
GDPR protects personal data privacy rights for individuals within the EU.
GDPR establishes explicit requirements such as data minimization, consent, rights to erasure, and breach notification obligations.

Key Concept

Regulatory Compliance and Legal Requirements Management
Rate this question