Question

Difficulty: Very hardRegulatory Compliance and Legal Requirements Management

Match each organizational compliance scenario to the specific regulatory mandate or statutory framework that governs its security and privacy controls.

  • A defense contractor developing satellite control software must restrict remote technical data access exclusively to U.S. persons to avoid illegal export of sensitive cryptographic source code.International Traffic in Arms Regulations (ITAR)
  • A non-bank financial service provider must designate a Qualified Individual to oversee its information security program and mandate multi-factor authentication for accessing customer financial records.GLBA Safeguards Rule
  • A European financial institution must conduct threat-led penetration testing and enforce comprehensive security risk oversight over critical third-party information technology service providers.Digital Operational Resilience Act (DORA)
  • A consumer platform operating in California must provide users with an explicit statutory right to opt out of having their personal profiles sold or shared for cross-context behavioral advertising.California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)

Answer

Each enterprise compliance requirement maps directly to its statutory or regulatory framework: restriction of defense software technical data to U.S. persons maps to ITAR; governance of non-bank financial customer data overseen by a Qualified Individual maps to the GLBA Safeguards Rule; European financial sector ICT resilience and third-party risk oversight maps to DORA; and state-level consumer opt-out rights for data selling/sharing maps to CCPA/CPRA.
Each organizational requirement aligns strictly with its governing framework: defense satellite technical data falls under ITAR; non-bank customer record security under the GLBA Safeguards Rule; EU financial sector ICT operational resilience under DORA; and consumer privacy rights allowing opt-out of data selling under CCPA/CPRA.

Step-by-Step Solution

1
Analyze the technical defense software access control requirement
Identified defense article technical data export restrictions limiting access strictly to U.S. persons
ITAR controls technical data and source code associated with defense technology items under the U.S. Munitions List.
2
Evaluate the non-bank financial institution governance scenario
Matched mandatory Qualified Individual designation and access control enforcement
The FTC GLBA Safeguards Rule establishes explicit security program governance requirements for financial institutions.
3
Evaluate the EU financial sector operational resilience and third-party risk scenario
Identified ICT operational resilience and security testing obligations
DORA enforces binding digital operational resilience standards across European financial entities.
4
Evaluate the consumer privacy data transfer opt-out requirement
Matched statutory opt-out rights for consumer personal data processing and advertising sales
CCPA/CPRA mandates clear mechanisms for consumers to restrict the selling or sharing of personal data.

Key Concept

Organizational Compliance Mandates and Regulatory Framework Alignment
Rate this question