Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

An organization is evaluating its compliance obligations across several distinct operational domains. Match each regulatory framework or standard on the left with its corresponding primary compliance mandate or protected data scope on the right.

  • PCI DSSMandates technical and operational security requirements to protect payment card cardholder data environments.
  • HIPAASafeguards electronic protected health information (ePHI) created, processed, or stored by covered entities and business associates.
  • Sarbanes-Oxley Act (SOX)Requires public corporate entities to implement strict internal IT controls over financial data reporting integrity.
  • FERPAProtects the privacy of student educational records in educational institutions receiving federal funding.

Answer

PCI DSS matches with safeguarding cardholder data environments; HIPAA matches with protecting electronic protected health information (ePHI); Sarbanes-Oxley Act (SOX) matches with maintaining internal controls over financial reporting IT systems; FERPA matches with protecting the privacy of student educational records.
Each regulatory framework is correctly paired with its targeted data classification and domain scope: PCI DSS protects cardholder data; HIPAA safeguards electronic protected health information (ePHI); SOX governs internal financial controls for public corporations; FERPA protects student educational records.

Step-by-Step Solution

1
Identify the data scope for PCI DSS
PCI DSS governs Payment Card Industry data and cardholder data environments (CDE).
Payment card security standards strictly dictate encryption, segmentation, and access controls for payment processing.
2
Identify the regulated entities and data for HIPAA
HIPAA regulates covered health entities and ePHI.
Health insurance and care records require administrative, physical, and technical safeguards under the Security and Privacy Rules.
3
Determine the accounting and corporate mandate for SOX
SOX regulates internal controls for financial systems in public companies.
Section 404 mandates verifiable IT controls to ensure financial statements are trustworthy and tamper-proof.
4
Determine the academic data scope for FERPA
FERPA regulates educational records in US educational institutions.
Educational institutions receiving federal funds must restrict access to student records without prior consent.

Key Concept

Regulatory Framework Mandates and Data Scopes
Rate this question