An IT support technician is configuring a local backup script on a workstation used by a financial services firm's human resources department. The workstation stores records containing national identification numbers, home addresses, and bank details of European Union residents. The department manager asks the technician to ensure the backup workflow complies with General Data Protection Regulation (GDPR) requirements for protecting this personally identifiable information (PII). Which of the following technical controls should the technician implement to meet GDPR compliance standards?
- Apply strong cryptographic encryption to the backups at rest and in transit while enforcing least privilege access controls.Cevap
- BIsolate the workstation on a separate VLAN that allows cleartext data transmission locally while blocking external internet access.
- CAnonymize the backup transaction logs while retaining national identification numbers in plaintext to simplify compliance auditing.
- DPerform daily physical degaussing of the workstation's local primary storage drive after every completed backup cycle.
Cevap
Apply strong cryptographic encryption to the backups at rest and in transit while enforcing least privilege access controls.
Under General Data Protection Regulation (GDPR) guidelines, organizations handling personally identifiable information (PII) of EU citizens must implement appropriate technical security measures. Applying end-to-end encryption for data both at rest (stored backups) and in transit (network transfers), combined with access restricted by least privilege, ensures confidentiality and regulatory compliance.
Adım Adım Çözüm
Anahtar Kavram
Data Privacy Regulations (GDPR and PII Protection)
Tahmini Süre:1m 30s