A systems administrator is reviewing IT security controls and compliance directives across various enterprise operational units. Match each compliance regulation or framework to the technical mandate or data handling restriction it strictly enforces.
- PCI-DSSProhibits the storage of full primary account numbers (PAN) and sensitive authentication data post-authorization.
- GDPRGrants individuals the legal right to request the permanent deletion of their personal data (right to erasure).
- HIPAAMandates technical and physical safeguards for protected health information (PHI) stored or transmitted by covered entities.
- FERPARestricts non-consensual disclosure of student educational records and academic progress data.
Cevap
PCI-DSS matches with prohibiting storage of full primary account numbers post-authorization; GDPR matches with granting individuals the right to request permanent deletion of their personal data; HIPAA matches with mandating technical and physical safeguards for protected health information; FERPA matches with restricting non-consensual disclosure of student educational records.
Each framework targets a specific data classification: PCI-DSS for payment card data, GDPR for EU consumer PII and data rights, HIPAA for patient PHI, and FERPA for student educational records.
Adım Adım Çözüm
Anahtar Kavram
Data Privacy Frameworks and Compliance Scopes