A financial technology SaaS provider headquartered in Canada expands its operations to process real-time payment transactions and consumer credit metrics for financial institutions operating in both the European Union and the United States. During a legal compliance audit, the enterprise risk management team evaluates the organization's regulatory obligations regarding stored cardholder data, non-public personal information (NPI), and financial telemetry. Which of the following requirements MUST the organization implement to achieve compliance with PCI DSS and GDPR mandates? (Select TWO.)
- Encrypt stored primary account numbers (PAN) and maintain a logically segregated cardholder data environment (CDE).Cevap
- Designate a statutory Data Protection Officer (DPO) and establish lawful cross-border data transfer mechanisms for EU personal data.Cevap
- CDeploy an inline network intrusion prevention system (IPS) to satisfy mandatory technical controls under Sarbanes-Oxley Act (SOX) Section 404.
- DRelocate all physical data storage infrastructure to United States soil to satisfy Gramm-Leach-Bliley Act (GLBA) data residency directives.
Cevap
The organization must encrypt stored primary account numbers (PAN) within a segregated cardholder data environment under PCI DSS, and designate a statutory Data Protection Officer (DPO) alongside lawful cross-border transfer mechanisms under GDPR.
Encrypting primary account numbers within a segregated cardholder data environment satisfies PCI DSS core security requirements. Appointing a Data Protection Officer and establishing lawful transfer mechanisms fulfills GDPR Articles 37 and 44 for processing EU personal data.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance Scope and Framework Control Requirements