Question

Difficulty: Very hardRegulatory Compliance and Legal Requirements Management

A financial technology SaaS provider headquartered in Canada expands its operations to process real-time payment transactions and consumer credit metrics for financial institutions operating in both the European Union and the United States. During a legal compliance audit, the enterprise risk management team evaluates the organization's regulatory obligations regarding stored cardholder data, non-public personal information (NPI), and financial telemetry. Which of the following requirements MUST the organization implement to achieve compliance with PCI DSS and GDPR mandates? (Select TWO.)

  1. Encrypt stored primary account numbers (PAN) and maintain a logically segregated cardholder data environment (CDE).Answer
  2. Designate a statutory Data Protection Officer (DPO) and establish lawful cross-border data transfer mechanisms for EU personal data.Answer
  3. C
    Deploy an inline network intrusion prevention system (IPS) to satisfy mandatory technical controls under Sarbanes-Oxley Act (SOX) Section 404.
  4. D
    Relocate all physical data storage infrastructure to United States soil to satisfy Gramm-Leach-Bliley Act (GLBA) data residency directives.

Answer

The organization must encrypt stored primary account numbers (PAN) within a segregated cardholder data environment under PCI DSS, and designate a statutory Data Protection Officer (DPO) alongside lawful cross-border transfer mechanisms under GDPR.
Encrypting primary account numbers within a segregated cardholder data environment satisfies PCI DSS core security requirements. Appointing a Data Protection Officer and establishing lawful transfer mechanisms fulfills GDPR Articles 37 and 44 for processing EU personal data.

Step-by-Step Solution

1
Analyze PCI DSS compliance obligations for processing cardholder payment data.
PCI DSS mandates the protection of stored cardholder data (PAN) through robust encryption algorithms and logical isolation of the Cardholder Data Environment (CDE).
Cardholder data security is a foundational requirement of PCI DSS for all payment-processing entities.
2
Analyze GDPR compliance obligations for handling personal telemetry of European Union residents.
GDPR mandates formal data governance oversight, including designating a Data Protection Officer (DPO) for large-scale data handling and adopting lawful cross-border data transfer safeguards.
GDPR applies extra-territorially to any global organization processing personal data of individuals within the EU.
3
Evaluate incorrect options regarding SOX Section 404 and GLBA mandates.
SOX Section 404 addresses internal accounting controls over financial disclosures rather than technical IPS appliance deployment, while GLBA dictates information security program safeguards rather than geographic server localization.
Regulatory compliance requires accurate mapping of statutory mandates to their specific scope and baseline requirements.

Key Concept

Regulatory Compliance Scope and Framework Control Requirements
Rate this question