200-201 · Question #116
Which two compliance frameworks require that data be encrypted when it is transmitted over a public network? (Choose two.)
The correct answer is A. PCI C. HIPAA. PCI DSS and HIPAA are two compliance frameworks that explicitly mandate the encryption of sensitive data when it is transmitted over public networks to protect cardholder data and protected health information, respectively.
Question
Which two compliance frameworks require that data be encrypted when it is transmitted over a public network? (Choose two.)
Options
- APCI
- BGLBA
- CHIPAA
- DSOX
- ECOBIT
How the community answered
(36 responses)- A86% (31)
- B8% (3)
- D3% (1)
- E3% (1)
Why each option
PCI DSS and HIPAA are two compliance frameworks that explicitly mandate the encryption of sensitive data when it is transmitted over public networks to protect cardholder data and protected health information, respectively.
The Payment Card Industry Data Security Standard (PCI DSS) explicitly requires encryption of cardholder data when transmitted across open, public networks, specifically citing Strong Cryptography and security protocols like TLS. This protects sensitive payment information during transit.
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect the privacy of consumer financial information, but it is less prescriptive about specific technical controls like encryption over public networks compared to PCI DSS or HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires that covered entities and business associates implement technical safeguards to protect electronic protected health information (ePHI), which includes encrypting ePHI when it is transmitted over an electronic network. This ensures patient data confidentiality.
The Sarbanes-Oxley Act (SOX) focuses on corporate governance and financial reporting accuracy, requiring internal controls, but it does not specifically mandate data encryption for public network transmission as a direct technical control.
COBIT is an IT governance framework that provides guidance on IT management, but it is not a regulatory compliance framework that directly mandates technical controls like data encryption for public network transmission.
Concept tested: Data encryption requirements in compliance frameworks
Source: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/PCI%20DSS%20v4.0/PCI_DSS_v4-0_r1.pdf
Topics
Community Discussion
No community discussion yet for this question.