Soru

Zorluk: ZorRegulatory Compliance and Legal Requirements Management

A multinational logistics enterprise headquartered in the United States processes payment card transactions for international shipments, manages personal data of European Union residents, and reports internal audit controls as a publicly traded company. The chief information security officer (CISO) is updating the enterprise regulatory compliance matrix following a cloud migration. Which of the following operational obligations directly apply to this organization? (Select TWO.)

  1. Establishing a lawful basis for processing personal data and enforcing data minimization principles for European customer records.Cevap
  2. Isolating the cardholder data environment (CDE) with strict network segmentation and conducting periodic vulnerability assessments.Cevap
  3. C
    Transferring legal responsibility for internal financial reporting security controls to the infrastructure cloud provider.
  4. D
    Submitting mandatory breach notification reports to the U.S. Department of Health and Human Services (HHS) following payment data compromise.

Cevap

The organization must establish a lawful processing basis with data minimization under GDPR and maintain a secure, segregated cardholder data environment under PCI DSS.
Because the enterprise processes personal data belonging to EU residents, it falls directly within the extra-territorial scope of GDPR, necessitating a defined lawful processing basis and data minimization controls. Additionally, because the company directly processes payment cards for online orders, it is bound by PCI DSS mandates to isolate the Cardholder Data Environment (CDE) and run regular security scans.

Adım Adım Çözüm

1
Analyze the regulatory jurisdictions and data types present in the scenario.
Identified EU PII (governed by GDPR), payment card data (governed by PCI DSS), and publicly traded US financial reporting (governed by SOX).
Regulatory applicability is determined by geography, data classification, and corporate governance structure.
2
Evaluate compliance obligations for European Union resident data.
GDPR applies extra-territorially, requiring a lawful basis (e.g., consent or contractual necessity) and adherence to data minimization principles.
Organizations processing EU residents' PII must comply with GDPR regardless of corporate headquarters location.
3
Evaluate compliance obligations for credit card processing systems.
PCI DSS requires securing and isolating the cardholder data environment (CDE) using segmentation and vulnerability testing.
Any organization handling account numbers or cardholder details must comply with PCI DSS technical standards.
4
Examine distractors for shared responsibility and regulatory scope misclassifications.
Disqualified CSP delegation of SOX liability (SOX accountability stays with corporate officers) and HHS breach notification (HIPAA applies strictly to PHI).
Cloud contracts cannot transfer legal compliance duties for financial reporting, and HIPAA governs healthcare data, not credit cards.

Anahtar Kavram

Regulatory Compliance Scope, Data Classification, and Extraterritorial Jurisdiction
Tahmini Süre:2m 0s
Bu soruyu puanla