Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

An enterprise compliance officer is updating the organization's regulatory tracking matrix to align with global legal mandates and industry-specific security requirements. Match each regulatory framework or legal mandate on the left with its corresponding compliance scope or operational requirement on the right.

  • Children's Online Privacy Protection Act (COPPA)Mandates verifiable parental consent prior to collecting, using, or disclosing personal information online from children under 13 years of age.
  • International Traffic in Arms Regulations (ITAR)Controls export and import restrictions on defense-related technical data, military technologies, and space-related items to foreign persons or destinations.
  • Federal Information Security Modernization Act (FISMA)Requires United States federal agencies and their contractors to implement security controls according to NIST guidelines and maintain ongoing system risk assessments.
  • Digital Operational Resilience Act (DORA)Establishes European Union cybersecurity resilience requirements, mandatory threat-led penetration testing, and ICT third-party risk oversight for financial entities.

Answer

COPPA matches the mandate for verifiable parental consent before collecting data from children under 13; ITAR matches export restrictions on defense-related technical data; FISMA matches US federal agency security control requirements following NIST guidelines; DORA matches EU financial sector digital operational resilience and ICT vendor oversight requirements.
Each regulation is paired accurately with its legal jurisdiction and operational focus: COPPA protects children's online data privacy; ITAR controls defense technical data exports; FISMA enforces US federal agency information security controls via NIST standards; and DORA establishes EU financial sector ICT operational resilience standards.

Step-by-Step Solution

1
Analyze the scope of COPPA
COPPA specifically protects online privacy for children under 13 years old, requiring verifiable parental consent.
Identify the distinct target population and consent mandate associated with child privacy protection.
2
Analyze the scope of ITAR
ITAR controls defense-related technical data and military export restrictions.
Differentiate export control regulations governing defense technology from general commerce or data privacy laws.
3
Analyze the scope of FISMA
FISMA mandates security control implementation (such as NIST SP 800-53) for US federal agencies and contractors.
Recognize federal information system governance standards enforced within US government operations.
4
Analyze the scope of DORA
DORA enforces EU digital operational resilience, ICT threat testing, and third-party risk management for financial institutions.
Distinguish recent regional financial sector cyber resilience regulations from generic privacy laws.

Key Concept

Regulatory Compliance and Legal Requirements Management
Rate this question