CAS-003 · Question #676
A large, multinational company currently has two separate databases. One is used for ERP while the second is used for CRM To consolidate services and infrastructure, it is proposed to combine the…
The correct answer is B. There are specific regulatory requirements the company might be violating by combining these. The compliance manager's primary concern is that combining ERP and CRM databases may violate specific regulatory requirements. ERP systems typically handle financial, operational, and HR data subject to regulations such as SOX, while CRM systems hold customer PII subject to…
Question
A large, multinational company currently has two separate databases. One is used for ERP while the second is used for CRM To consolidate services and infrastructure, it is proposed to combine the databases. The company's compliance manager is asked to review the proposal and is concerned about this integration. Which of the following would pose the MOST concern to the compliance manager?
Options
- AThe attack surface of the combined database is lower than the previous separate systems, so
- BThere are specific regulatory requirements the company might be violating by combining these
- CBy consolidating services in this manner, there is an increased risk posed to the organization due
- DAuditing the combined database structure will require more short-term resources, as the new
How the community answered
(23 responses)- B83% (19)
- C4% (1)
- D13% (3)
Explanation
The compliance manager's primary concern is that combining ERP and CRM databases may violate specific regulatory requirements. ERP systems typically handle financial, operational, and HR data subject to regulations such as SOX, while CRM systems hold customer PII subject to regulations like GDPR, CCPA, or HIPAA depending on the industry. Combining these datasets may violate data minimization principles, access control requirements, or regulatory mandates that require certain categories of data to be kept logically or physically separate. It could also expose customer data to financial systems users who have no legitimate need for it, violating least-privilege and need-to-know principles mandated by compliance frameworks. Option A is incorrect - combining databases generally increases the attack surface, not decreases it. Option C describes a risk but is not specific enough to reflect a compliance manager's primary concern. Option D is an operational concern, not a compliance violation.
Topics
Community Discussion
No community discussion yet for this question.