CISM · Question #126
A financial institution is expanding to international jurisdictions and is mindful of protecting customer information. Which of the following should be of GREATEST concern?
The correct answer is C. Privacy laws and regulations for each country in which the organization operates. When expanding internationally, privacy laws and regulations are of greatest concern for a financial institution protecting customer information, as these dictate the legal requirements for handling sensitive data across different jurisdictions.
Question
A financial institution is expanding to international jurisdictions and is mindful of protecting customer information. Which of the following should be of GREATEST concern?
Options
- AAbility to monitor and enforce security controls in multiple jurisdictions
- BGlobal payment card industry regulations
- CPrivacy laws and regulations for each country in which the organization operates
- DInformation security resources available in each country in which the organization operates
How the community answered
(39 responses)- A5% (2)
- B3% (1)
- C79% (31)
- D13% (5)
Why each option
When expanding internationally, privacy laws and regulations are of greatest concern for a financial institution protecting customer information, as these dictate the legal requirements for handling sensitive data across different jurisdictions.
While important, monitoring and enforcing security controls is an operational challenge that arises *from* the need to comply with specific laws and regulations.
Global PCI regulations apply specifically to payment card data, but customer information encompasses a broader set of data protected by general privacy laws.
Privacy laws and regulations, such as GDPR or various national data protection acts, explicitly govern how customer information must be collected, stored, processed, and protected in each country, carrying significant legal and financial penalties for non-compliance. These laws directly impact the organization's ability to operate legally and maintain customer trust internationally.
Resource availability is a practical consideration for implementing security but doesn't define the *legal mandate* for protecting customer information.
Concept tested: International data privacy regulations
Topics
Community Discussion
No community discussion yet for this question.