Soru

Zorluk: OrtaData Privacy and Compliance Regulations

An IT technician is configuring a new web server for an international organization that processes payment card transactions and collects account details from European Union residents. Which of the following technical procedures must the technician perform to align with PCI-DSS and GDPR regulations? (Select TWO.)

  1. Encrypt stored payment card numbers and restrict access to authorized personnel to comply with PCI-DSS requirements.Cevap
  2. B
    Store card verification codes (CVV) permanently in database tables to simplify recurring billing audits.
  3. Establish automated mechanisms to purge personal identifying records upon valid customer deletion requests to support GDPR right to erasure.Cevap
  4. D
    Classify all internal system configuration files as Protected Health Information (PHI) under HIPAA guidelines.

Cevap

The technician must encrypt stored payment card data to comply with PCI-DSS standards and establish automated data purging workflows to respect the GDPR right to erasure.
Encrypting stored payment card numbers satisfies PCI-DSS requirements for protecting cardholder data. Implementing automated workflows to remove personal data upon request fulfills the GDPR requirement regarding the right to erasure (right to be forgotten).

Adım Adım Çözüm

1
Identify the relevant data privacy and security frameworks based on data types.
Payment card data falls under PCI-DSS, while EU resident personal data falls under GDPR.
Different data types mandate specific compliance procedures and regulations.
2
Evaluate the controls required for cardholder data under PCI-DSS.
Primary account numbers (PAN) must be encrypted during storage and transmission, whereas card verification values (CVV) must never be stored post-authorization.
PCI-DSS mandates strong cryptographic safeguards for cardholder data and prohibits storing sensitive authentication values after payment verification.
3
Evaluate the compliance obligations required for EU personal data under GDPR.
Organizations must comply with data subject rights, including the right to be forgotten (erasure).
GDPR empowers users to request the removal of their personal identifiable information (PII) from company systems.

Anahtar Kavram

Data Privacy and Compliance Regulations (PCI-DSS, GDPR, HIPAA)
Bu soruyu puanla