nerdexam
CompTIA

CAS-003 · Question #590

A Chief Information Security Officer (CISO) needs to create a policy set that meets international standards for data privacy and sharing. Which of the following should the CISO read and understand…

The correct answer is B. GDPR. GDPR is the primary international regulation governing personal data privacy and cross-border data sharing, making it essential reading before authoring related enterprise policies.

Risk Management

Question

A Chief Information Security Officer (CISO) needs to create a policy set that meets international standards for data privacy and sharing. Which of the following should the CISO read and understand before writing the policies?

Options

  • APCI DSS
  • BGDPR
  • CNIST
  • DISO 31000

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    94% (15)

Why each option

GDPR is the primary international regulation governing personal data privacy and cross-border data sharing, making it essential reading before authoring related enterprise policies.

APCI DSS

PCI DSS is a payment card industry security standard scoped specifically to organizations that handle cardholder data, not a broad international data privacy regulation.

BGDPRCorrect

The General Data Protection Regulation is an EU law that establishes the international standard for how personal data must be collected, stored, processed, and transferred across borders. Any organization handling the personal data of EU residents or operating internationally must align its data policies with GDPR principles such as lawful basis, data minimization, and data subject rights. A CISO writing policies intended to meet international standards must understand GDPR as the governing framework.

CNIST

NIST publishes cybersecurity frameworks and guidelines primarily for US government and voluntary private sector use and does not constitute an international data privacy law.

DISO 31000

ISO 31000 is an international risk management framework standard that addresses organizational risk processes broadly and does not govern data privacy or data sharing specifically.

Concept tested: International data privacy regulation - GDPR compliance

Source: https://gdpr.eu/what-is-gdpr/

Topics

#GDPR#data privacy#international compliance#regulatory frameworks

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice