Match each regulatory framework or standard to its primary compliance mandate.
- Payment Card Industry Data Security Standard (PCI DSS)Mandates technical and administrative safeguards to protect cardholder data during transaction processing and storage.
- Health Insurance Portability and Accountability Act (HIPAA)Establishes security and privacy rules to safeguard Protected Health Information (PHI).
- General Data Protection Regulation (GDPR)Enforces data privacy rights and explicit consent requirements for processing personal data of individuals in the EU.
- Sarbanes-Oxley Act (SOX)Requires public companies to maintain strict internal financial controls and audit log integrity.
Answer
PCI DSS matches cardholder data protection; HIPAA matches Protected Health Information (PHI) safeguards; GDPR matches EU personal data privacy rights; SOX matches corporate financial reporting and internal audit controls.
Each regulatory framework targets a distinct sector or data classification: PCI DSS protects cardholder data, HIPAA protects healthcare PHI, GDPR protects EU personal privacy rights, and SOX regulates public company financial accounting and audit logging.
Step-by-Step Solution
Key Concept
Regulatory Framework Mandates and Compliance Data Scope