Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

An enterprise risk analyst is auditing international compliance requirements across multiple regional jurisdictions and sector-specific legal mandates. Match each regulatory framework or law on the left with its core scope and applicability on the right.

  • NIS2 DirectiveEuropean Union directive establishing mandatory cybersecurity risk management and incident reporting for essential and important CNI entities.
  • PIPEDACanadian federal law governing how private-sector organizations collect, use, and disclose personal information during commercial activities.
  • CMMCUnited States defense standard requiring supply chain contractors handling Controlled Unclassified Information to obtain verified compliance levels.
  • EARUnited States export control regulations restricting the foreign distribution of dual-use commercial technologies, software, and technical data.

Answer

NIS2 Directive matches EU critical infrastructure cybersecurity risk management rules; PIPEDA matches Canadian private-sector commercial privacy laws; CMMC matches US DoD defense contractor cybersecurity verification for CUI; EAR matches US dual-use commercial export control regulations.
The correct pairings accurately map each regulation to its respective domain and scope. The NIS2 Directive enforces cyber resilience for essential entities in the European Union. PIPEDA regulates Canadian commercial privacy obligations. CMMC mandates verified cybersecurity practices for US defense contractors processing Controlled Unclassified Information. EAR governs export control restrictions on dual-use commercial items and technical data.

Step-by-Step Solution

1
Analyze the legal domain and jurisdiction for each mandate on the left.
NIS2 is European critical infrastructure resilience; PIPEDA is Canadian commercial data privacy; CMMC is US defense supply chain security; EAR is US dual-use export control.
Categorizing compliance frameworks by jurisdiction and protected data type is fundamental to regulatory mapping.
2
Match each mandate to its precise scope description on the right.
NIS2 aligns with EU essential entity security; PIPEDA aligns with Canadian commercial personal data; CMMC aligns with DoD contractor CUI assessments; EAR aligns with dual-use tech export restrictions.
Ensures accurate correlation between organizational activities and governing legal requirements.

Key Concept

Mapping regulatory compliance frameworks and legal requirements to organizational scope, geographical jurisdiction, and controlled data types.
Rate this question