An IT compliance auditor is updating the organization's data governance policy matrix. Match each data privacy framework or regulation on the left with its corresponding operational requirement or scope on the right.
- PCI-DSSProhibits the persistent storage of card verification codes (CVV/CVC) after transaction authorization.
- GDPRGrants individuals the right to request complete erasure of their personal data (Right to be Forgotten).
- HIPAARequires technical and administrative safeguards for electronic Protected Health Information (ePHI).
- FERPARestricts disclosure of student educational records and transcripts without explicit consent.
Cevap
PCI-DSS matches with prohibiting post-authorization CVV storage; GDPR matches with the Right to be Forgotten data erasure requirement; HIPAA matches with safeguarding electronic Protected Health Information (ePHI); FERPA matches with restricting disclosure of student educational records.
Each regulatory framework is correctly paired with its defining mandate: PCI-DSS covers payment card transaction processing and restricts CVV storage; GDPR outlines EU data privacy rights including data erasure; HIPAA establishes safeguards for healthcare ePHI; and FERPA protects educational records.
Adım Adım Çözüm
Anahtar Kavram
Data Privacy Regulations and Operational Scopes (GDPR, HIPAA, PCI-DSS, FERPA)