Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A multinational cloud software provider processes user profiles (including names, email addresses, and location data) for European users while accepting credit card payments for subscriptions worldwide. Following a recent compliance gap analysis, the Chief Information Security Officer (CISO) is updating the organization's legal and regulatory compliance framework. Which of the following technical and operational requirements must the organization implement to satisfy both GDPR and PCI DSS compliance obligations? (Select TWO.)

  1. Apply strong cryptographic controls to obscure stored Primary Account Numbers (PAN) and mandate secure transmission of payment card data across public networks.Answer
  2. Establish formal processes to fulfill data subject erasure requests and maintain a valid legal basis for processing personal data.Answer
  3. C
    Execute a Business Associate Agreement (BAA) prior to processing any credit card details or location tracking telemetry.
  4. D
    Deploy network-level stateful firewalls as the sole required control to guarantee user right-to-erasure obligations under data protection regulations.

Answer

The organization must apply strong cryptographic controls to stored and transmitted Primary Account Numbers (PAN) for PCI DSS compliance, and establish processes to fulfill data subject erasure requests and legal basis requirements for GDPR compliance.
The correct requirements are protecting payment card numbers (PAN) via strong encryption to comply with PCI DSS standards, and establishing procedures for handling data subject erasure requests to comply with GDPR obligations.

Step-by-Step Solution

1
Analyze data scope and governing regulations
Identified Payment Card Industry Data Security Standard (PCI DSS) for payment card details (PAN) and General Data Protection Regulation (GDPR) for European user profiles.
Regulatory scope depends on the classification of data being collected and processed.
2
Evaluate PCI DSS requirements
PCI DSS mandates protection of Cardholder Data Environment (CDE), specifically encryption of PAN at rest and in transit.
Ensures credit card numbers cannot be intercepted or extracted in plaintext.
3
Evaluate GDPR requirements
GDPR grants rights to data subjects, including the right to erasure (right to be forgotten) and mandates lawful processing.
Protects individuals' privacy rights over their personal data.

Key Concept

Regulatory Compliance and Legal Requirements Management
Rate this question