A multinational logistics enterprise headquartered in the United States processes payment card transactions for international shipments, manages personal data of European Union residents, and reports internal audit controls as a publicly traded company. The chief information security officer (CISO) is updating the enterprise regulatory compliance matrix following a cloud migration. Which of the following operational obligations directly apply to this organization? (Select TWO.)
- Establishing a lawful basis for processing personal data and enforcing data minimization principles for European customer records.Answer
- Isolating the cardholder data environment (CDE) with strict network segmentation and conducting periodic vulnerability assessments.Answer
- CTransferring legal responsibility for internal financial reporting security controls to the infrastructure cloud provider.
- DSubmitting mandatory breach notification reports to the U.S. Department of Health and Human Services (HHS) following payment data compromise.
Answer
The organization must establish a lawful processing basis with data minimization under GDPR and maintain a secure, segregated cardholder data environment under PCI DSS.
Because the enterprise processes personal data belonging to EU residents, it falls directly within the extra-territorial scope of GDPR, necessitating a defined lawful processing basis and data minimization controls. Additionally, because the company directly processes payment cards for online orders, it is bound by PCI DSS mandates to isolate the Cardholder Data Environment (CDE) and run regular security scans.
Step-by-Step Solution
Key Concept
Regulatory Compliance Scope, Data Classification, and Extraterritorial Jurisdiction
Estimated Time:2m 0s