A multinational cloud software provider processes user profiles (including names, email addresses, and location data) for European users while accepting credit card payments for subscriptions worldwide. Following a recent compliance gap analysis, the Chief Information Security Officer (CISO) is updating the organization's legal and regulatory compliance framework. Which of the following technical and operational requirements must the organization implement to satisfy both GDPR and PCI DSS compliance obligations? (Select TWO.)
- Apply strong cryptographic controls to obscure stored Primary Account Numbers (PAN) and mandate secure transmission of payment card data across public networks.Cevap
- Establish formal processes to fulfill data subject erasure requests and maintain a valid legal basis for processing personal data.Cevap
- CExecute a Business Associate Agreement (BAA) prior to processing any credit card details or location tracking telemetry.
- DDeploy network-level stateful firewalls as the sole required control to guarantee user right-to-erasure obligations under data protection regulations.
Cevap
The organization must apply strong cryptographic controls to stored and transmitted Primary Account Numbers (PAN) for PCI DSS compliance, and establish processes to fulfill data subject erasure requests and legal basis requirements for GDPR compliance.
The correct requirements are protecting payment card numbers (PAN) via strong encryption to comply with PCI DSS standards, and establishing procedures for handling data subject erasure requests to comply with GDPR obligations.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance and Legal Requirements Management