Soru

Zorluk: KolayRegulatory Compliance and Legal Requirements Management

A retail business operating in the European Union accepts online credit card payments from local customers. The security team must update company policies to maintain compliance when handling customer payment card details and personal billing addresses. Which of the following compliance frameworks directly govern the security and privacy of these data types? (Select TWO.)

  1. Payment Card Industry Data Security Standard (PCI-DSS) for protecting payment cardholder dataCevap
  2. B
    Health Insurance Portability and Accountability Act (HIPAA) for protecting medical health records
  3. General Data Protection Regulation (GDPR) for safeguarding personal data of individuals in the EUCevap
  4. D
    Sarbanes-Oxley Act (SOX) for auditing corporate financial accounting statements

Cevap

The Payment Card Industry Data Security Standard (PCI-DSS) and the General Data Protection Regulation (GDPR) are the two compliance frameworks that directly apply to credit card processing and EU customer personal billing data.
The Payment Card Industry Data Security Standard (PCI-DSS) sets security controls for handling credit card numbers and payment data. The General Data Protection Regulation (GDPR) enforces privacy and data protection rights for personal data collected from individuals in the European Union.

Adım Adım Çözüm

1
Identify the specific data types processed in the scenario
The scenario includes primary credit card numbers (cardholder data) and customer names/billing addresses (EU resident personal data).
Determining applicable compliance standards requires analyzing data classification and subject location.
2
Match data classifications to their governing regulations
PCI-DSS enforces security controls on cardholder data, while GDPR governs privacy controls for EU personal data.
Each compliance framework has specific jurisdiction and scope boundaries based on data type and geographic region.

Anahtar Kavram

Identifying regulatory scope based on data classification (Cardholder Data vs. PII) to apply appropriate compliance frameworks such as PCI-DSS and GDPR.
Tahmini Süre:45s
Bu soruyu puanla