A cloud-native SaaS provider headquartered in Japan processes real-time telemetry, transaction records, and personally identifiable information (PII) for subscribers across the European Union and North America. Following an internal compliance review prior to a public stock listing, the Chief Information Security Officer (CISO) mandates that technical security controls for data handling must satisfy regional privacy laws, data sovereignty requirements, and financial oversight controls. Which of the following governance strategies best aligns the organization's technical controls with these legal and regulatory obligations?
- Implement localized data encryption using region-specific customer-managed keys to satisfy data privacy mandates while maintaining centralized, immutable audit logging for financial oversight.Cevap
- BDeploy perimeter web application firewalls and network segmentation as a compensating administrative control to exempt cross-border data transfers from regional data protection obligations.
- CApply asymmetric encryption algorithms for bulk data-at-rest storage while disabling audit logging to prevent PII exposure to internal and external financial compliance auditors.
- DReclassify all subscriber financial transaction records as non-sensitive operational telemetry data to bypass statutory data retention and privacy audit frameworks.
Cevap
Implementing localized data encryption with region-specific customer-managed keys alongside centralized, immutable audit logging best satisfies both regional privacy regulations and financial oversight standards.
The correct option addresses both aspects of the scenario: localized cryptographic key control satisfies regional privacy regulations and data sovereignty requirements, while centralized immutable logging preserves the audit trails required for financial reporting governance.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance and Legal Requirements Management