An organization is evaluating its compliance obligations across several distinct operational domains. Match each regulatory framework or standard on the left with its corresponding primary compliance mandate or protected data scope on the right.
- PCI DSSMandates technical and operational security requirements to protect payment card cardholder data environments.
- HIPAASafeguards electronic protected health information (ePHI) created, processed, or stored by covered entities and business associates.
- Sarbanes-Oxley Act (SOX)Requires public corporate entities to implement strict internal IT controls over financial data reporting integrity.
- FERPAProtects the privacy of student educational records in educational institutions receiving federal funding.
Cevap
PCI DSS matches with safeguarding cardholder data environments; HIPAA matches with protecting electronic protected health information (ePHI); Sarbanes-Oxley Act (SOX) matches with maintaining internal controls over financial reporting IT systems; FERPA matches with protecting the privacy of student educational records.
Each regulatory framework is correctly paired with its targeted data classification and domain scope: PCI DSS protects cardholder data; HIPAA safeguards electronic protected health information (ePHI); SOX governs internal financial controls for public corporations; FERPA protects student educational records.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Framework Mandates and Data Scopes