Soru

Zorluk: ZorRegulatory Compliance and Legal Requirements Management

A cloud-native SaaS provider headquartered in Japan processes real-time telemetry, transaction records, and personally identifiable information (PII) for subscribers across the European Union and North America. Following an internal compliance review prior to a public stock listing, the Chief Information Security Officer (CISO) mandates that technical security controls for data handling must satisfy regional privacy laws, data sovereignty requirements, and financial oversight controls. Which of the following governance strategies best aligns the organization's technical controls with these legal and regulatory obligations?

  1. Implement localized data encryption using region-specific customer-managed keys to satisfy data privacy mandates while maintaining centralized, immutable audit logging for financial oversight.Cevap
  2. B
    Deploy perimeter web application firewalls and network segmentation as a compensating administrative control to exempt cross-border data transfers from regional data protection obligations.
  3. C
    Apply asymmetric encryption algorithms for bulk data-at-rest storage while disabling audit logging to prevent PII exposure to internal and external financial compliance auditors.
  4. D
    Reclassify all subscriber financial transaction records as non-sensitive operational telemetry data to bypass statutory data retention and privacy audit frameworks.

Cevap

Implementing localized data encryption with region-specific customer-managed keys alongside centralized, immutable audit logging best satisfies both regional privacy regulations and financial oversight standards.
The correct option addresses both aspects of the scenario: localized cryptographic key control satisfies regional privacy regulations and data sovereignty requirements, while centralized immutable logging preserves the audit trails required for financial reporting governance.

Adım Adım Çözüm

1
Analyze organizational compliance obligations across operating jurisdictions.
Identified cross-border requirements including regional privacy/sovereignty mandates for subscriber PII and strict auditability/retention mandates for financial records.
Multinational organizations must adhere to statutory requirements in every region where data is collected or processed.
2
Evaluate technical and governance controls against identified regulatory mandates.
Regionally managed cryptographic keys enforce data sovereignty and privacy, while centralized immutable logs support global financial oversight and non-repudiation.
Security architecture must balance localized privacy boundaries with centralized administrative audit requirements.
3
Select the option that correctly satisfies both privacy and financial compliance without violating control functions or legal scopes.
The strategy combining localized encryption key management with immutable audit logging provides complete compliance alignment.
This strategy correctly applies technical control types without attempting invalid legal exemptions or improper data reclassifications.

Anahtar Kavram

Regulatory Compliance and Legal Requirements Management
Bu soruyu puanla