nerdexam
Isaca

CCAK · Question #72

Which of the following is the BEST control framework for a European manufacturing corporation that is migrating to the cloud?

The correct answer is D. EU GDPR. EU GDPR (General Data Protection Regulation) is the most appropriate because it is a legally binding regulation that all European organizations processing personal data must comply with - regardless of industry or technology. Non-compliance carries significant financial…

Cloud Compliance

Question

Which of the following is the BEST control framework for a European manufacturing corporation that is migrating to the cloud?

Options

  • ANIST SP 800-53
  • BCSA's GDPR CoC
  • CPCI-DSS
  • DEU GDPR

How the community answered

(44 responses)
  • A
    5% (2)
  • B
    20% (9)
  • C
    9% (4)
  • D
    66% (29)

Explanation

EU GDPR (General Data Protection Regulation) is the most appropriate because it is a legally binding regulation that all European organizations processing personal data must comply with - regardless of industry or technology. Non-compliance carries significant financial penalties. NIST SP 800-53 is US-focused and government-oriented. PCI-DSS applies specifically to payment card data. CSA's GDPR CoC is cloud-specific but narrower than GDPR itself. For a European entity, GDPR compliance is a legal obligation that supersedes optional frameworks.

Topics

#GDPR Compliance#Control Frameworks#Cloud Regulations#Data Protection

Community Discussion

No community discussion yet for this question.

Full CCAK Practice