A multinational fintech enterprise headquartered in Canada hosts its core payment processing and accounting platform in an IaaS cloud environment. The platform processes customer credit card transactions while also storing records subject to Sarbanes-Oxley (SOX) compliance for financial reporting integrity. Which of the following compliance actions and technical security controls must the organization enforce to satisfy these legal and regulatory frameworks? (Select TWO.)
- Implement strict access control policies, segregation of duties, and immutable logging for database systems housing financial statements.Answer
- BTransfer legal liability and user data governance obligations to the cloud service provider through the IaaS service level agreement.
- Isolate the Cardholder Data Environment (CDE) through network segmentation and enforce strong encryption on stored primary account numbers.Answer
- DRely on perimeter network firewalls as the primary technical control to mitigate application-layer software flaws within custom accounting modules.
Answer
The organization must implement strict access control policies, segregation of duties, and immutable logging for financial reporting systems (SOX requirement), and isolate the Cardholder Data Environment (CDE) while encrypting stored account numbers (PCI-DSS requirement).
Establishing strict access control policies, segregation of duties, and audit logging for financial databases directly satisfies SOX Section 404 mandates regarding internal control over financial reporting. Simultaneously, isolating the Cardholder Data Environment (CDE) and encrypting primary account numbers directly aligns with PCI-DSS requirements for protecting payment data.
Step-by-Step Solution
Key Concept
Regulatory Compliance Alignment and Mandatory Control Verification