Soru

Zorluk: ZorData Privacy and Compliance Regulations

A systems administrator at a multinational e-commerce company is auditing network architecture and storage policies for an online store that processes credit card transactions and maintains profile details for customers residing in the European Union. Which TWO of the following operational controls must the administrator implement to satisfy PCI-DSS and GDPR requirements?

  1. Segment the network hosting the cardholder data environment (CDE) from non-payment web application systems.Cevap
  2. Establish a documented workflow to process customer requests for the complete deletion of their personal data.Cevap
  3. C
    Store customer credit card CVV security codes in an encrypted database vault for automatic subscription renewals.
  4. D
    Apply FERPA privacy controls to customer support ticket logs and contact histories.

Cevap

The administrator must segment the cardholder data environment (CDE) from other non-payment web infrastructure to satisfy PCI-DSS standards and establish a procedure for handling customer requests for complete personal data erasure to comply with GDPR.
Segmenting the cardholder data environment (CDE) limits the scope of PCI-DSS audits and prevents unauthorized access across web segments. Implementing a data deletion request process satisfies the GDPR 'Right to Erasure' (Right to be Forgotten) requirement for EU citizens.

Adım Adım Çözüm

1
Analyze PCI-DSS requirements for handling payment card transactions.
Identified that cardholder data environment (CDE) network segmentation is required and that storing CVV codes post-authorization is strictly forbidden.
PCI-DSS governs payment card security controls and limits post-authorization storage of sensitive verification data.
2
Analyze GDPR requirements for processing European Union customer personal data.
Identified that data subjects have the right to request deletion of their personal data (Right to Erasure).
GDPR grants EU citizens explicit rights over their personal identifiable information (PII).
3
Evaluate and reject improper regulation applications.
Determined that FERPA applies only to educational institutions and student records, making it irrelevant to e-commerce customer data.
Selecting the incorrect regulatory framework leads to misconfigured security controls and non-compliance.

Anahtar Kavram

Identifying operational scope and technical compliance controls for PCI-DSS and GDPR
Bu soruyu puanla