A multinational streaming entertainment company based in Brazil expands operations into the European Union and the United States. During an annual audit, the Chief Information Security Officer (CISO) reviews legal and compliance obligations for managing customer profiles and payment processing environments. Which of the following requirements must the organization implement to satisfy both GDPR and PCI-DSS compliance mandates? (Select TWO.)
- Provide technical mechanisms allowing European data subjects to request the erasure of their personal information within statutory timeframes.Cevap
- Restrict system access to cardholder data strictly to personnel whose specified job functions require such access.Cevap
- CDeploy network perimeter firewalls as the primary control to prevent application-level memory buffer overflow exploits.
- DClassify routine application log maintenance as a preventive physical control within the governance baseline.
Cevap
The organization must implement mechanisms to honor data erasure requests under GDPR and restrict cardholder data access strictly based on business need-to-know under PCI-DSS.
Enabling mechanisms for users to request data deletion fulfills GDPR data subject rights for personal data, while restricting cardholder data access to job-related duties satisfies PCI-DSS access control rules.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance and Legal Requirements Management