Soru

Zorluk: ZorRegulatory Compliance and Legal Requirements Management

A United States-based mortgage technology provider processes personal financial records and loan applications for regional banks. The organization plans to migrate its infrastructure to a multi-tenant public cloud model while maintaining remote administration capabilities for offshore engineering teams. During a compliance evaluation, the Chief Information Security Officer (CISO) must ensure alignment with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding administrative and technical data protections. Which of the following strategies best fulfills the legal compliance requirements for safeguarding consumer financial data in this architecture?

  1. Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.Cevap
  2. B
    Implement a public key infrastructure certificate policy that classifies offshore developers as data owners to legally delegate risk liability to the third-party contractor.
  3. C
    Deploy network-level intrusion prevention firewalls at the cloud perimeter while relying on standard password authentication for internal engineering access.
  4. D
    Restrict data processing strictly to local hardware by establishing an air-gapped network segment without cloud backup services.

Cevap

Mandate multi-factor authentication for all personnel accessing customer financial systems, enforce data encryption in transit and at rest, and designate a qualified individual to oversee the information security program.
The correct option directly implements the explicit requirements outlined in the FTC GLBA Safeguards Rule. Under GLBA, financial entities and their service providers must protect consumer non-public personal information by implementing technical safeguards—such as multi-factor authentication and data encryption both at rest and in transit—and administrative safeguards, such as designating a qualified individual to manage and oversee the security program.

Adım Adım Çözüm

1
Identify the primary governing regulation and its scope.
The target organization handles non-public personal financial information for banking customers, bringing it directly under the jurisdiction of the FTC Gramm-Leach-Bliley Act (GLBA) Safeguards Rule.
Regulatory compliance mandates depend on aligning technical controls directly with the statutory obligations of the specific governing framework.
2
Analyze the mandatory administrative and technical safeguards required under the GLBA Safeguards Rule updates.
The rule mandates specific baseline controls: robust access controls including multi-factor authentication (MFA) for accessing customer data, encryption of data at rest and in transit, continuous monitoring or vulnerability testing, and administrative oversight by a designated qualified individual.
Financial privacy regulations mandate both administrative accountability and rigorous technical controls to protect non-public personal information.
3
Evaluate the proposed operational options against these regulatory requirements.
Enforcing MFA, implementing end-to-end encryption for storage and transit in the cloud environment, and appointing a qualified individual directly fulfills the statutory requirements of the GLBA Safeguards Rule.
This combination addresses both technical protection measures for multi-tenant/offshore access and formal governance oversight required by law.

Anahtar Kavram

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Requirements
Tahmini Süre:2m 0s
Bu soruyu puanla