An enterprise risk analyst is auditing international compliance requirements across multiple regional jurisdictions and sector-specific legal mandates. Match each regulatory framework or law on the left with its core scope and applicability on the right.
- NIS2 DirectiveEuropean Union directive establishing mandatory cybersecurity risk management and incident reporting for essential and important CNI entities.
- PIPEDACanadian federal law governing how private-sector organizations collect, use, and disclose personal information during commercial activities.
- CMMCUnited States defense standard requiring supply chain contractors handling Controlled Unclassified Information to obtain verified compliance levels.
- EARUnited States export control regulations restricting the foreign distribution of dual-use commercial technologies, software, and technical data.
Answer
NIS2 Directive matches EU critical infrastructure cybersecurity risk management rules; PIPEDA matches Canadian private-sector commercial privacy laws; CMMC matches US DoD defense contractor cybersecurity verification for CUI; EAR matches US dual-use commercial export control regulations.
The correct pairings accurately map each regulation to its respective domain and scope. The NIS2 Directive enforces cyber resilience for essential entities in the European Union. PIPEDA regulates Canadian commercial privacy obligations. CMMC mandates verified cybersecurity practices for US defense contractors processing Controlled Unclassified Information. EAR governs export control restrictions on dual-use commercial items and technical data.
Step-by-Step Solution
Key Concept
Mapping regulatory compliance frameworks and legal requirements to organizational scope, geographical jurisdiction, and controlled data types.