Soru

Zorluk: OrtaData Privacy and Compliance Regulations

A systems administrator is setting up storage and backup policies for a web application database that processes personal information of customers residing in the European Union. Which of the following technical controls and compliance procedures must be implemented to comply with the General Data Protection Regulation (GDPR)? (Select TWO.)

  1. Implement technical mechanisms to permanently delete an individual's personal data upon receiving a valid request.Cevap
  2. Apply strong cryptographic encryption to personal data both in transit and at rest.Cevap
  3. C
    Retain full card verification value (CVV) magnetic stripe data in plaintext to assist with annual compliance audits.
  4. D
    Enforce Business Associate Agreements (BAAs) with all international third-party cloud service providers.

Cevap

The correct controls to implement are providing technical mechanisms to permanently delete an individual's personal data upon request and applying strong cryptographic encryption to personal data in transit and at rest.
Under GDPR, organizations processing personal data of EU residents must implement robust technical protections, such as encrypting personal data in transit and at rest, while also adhering to individual data subject rights, specifically providing technical means to permanently delete personal data upon request (Right to Erasure).

Adım Adım Çözüm

1
Identify the governing regulatory framework based on the geographic and data scope.
The target compliance framework is GDPR because the application processes personal data (PII) of European Union citizens.
GDPR applies specifically to entities collecting or processing personal data belonging to EU residents.
2
Evaluate required technical safeguards and individual rights mandated by GDPR.
GDPR mandates data protection mechanisms including encryption in transit and at rest as well as honoring data subject rights like the Right to Erasure ('Right to be Forgotten').
Organizations must safeguard data integrity and confidentiality while providing users control over their stored personal data.
3
Identify and reject misapplied controls from other regulatory standards.
Storing card verification values violates PCI-DSS rules, and Business Associate Agreements pertain to HIPAA compliance, making both distractor options incorrect.
Confusing PCI-DSS payment card restrictions or HIPAA healthcare agreements with GDPR personal data requirements represents a scope misinterpretation.

Anahtar Kavram

GDPR Technical Safeguards and Data Subject Rights
Bu soruyu puanla