nerdexam
Isaca

CISM · Question #126

A financial institution is expanding to international jurisdictions and is mindful of protecting customer information. Which of the following should be of GREATEST concern?

The correct answer is C. Privacy laws and regulations for each country in which the organization operates. When expanding internationally, privacy laws and regulations are of greatest concern for a financial institution protecting customer information, as these dictate the legal requirements for handling sensitive data across different jurisdictions.

Submitted by jakub_pl· Apr 18, 2026Information Security Risk Management

Question

A financial institution is expanding to international jurisdictions and is mindful of protecting customer information. Which of the following should be of GREATEST concern?

Options

  • AAbility to monitor and enforce security controls in multiple jurisdictions
  • BGlobal payment card industry regulations
  • CPrivacy laws and regulations for each country in which the organization operates
  • DInformation security resources available in each country in which the organization operates

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    79% (31)
  • D
    13% (5)

Why each option

When expanding internationally, privacy laws and regulations are of greatest concern for a financial institution protecting customer information, as these dictate the legal requirements for handling sensitive data across different jurisdictions.

AAbility to monitor and enforce security controls in multiple jurisdictions

While important, monitoring and enforcing security controls is an operational challenge that arises *from* the need to comply with specific laws and regulations.

BGlobal payment card industry regulations

Global PCI regulations apply specifically to payment card data, but customer information encompasses a broader set of data protected by general privacy laws.

CPrivacy laws and regulations for each country in which the organization operatesCorrect

Privacy laws and regulations, such as GDPR or various national data protection acts, explicitly govern how customer information must be collected, stored, processed, and protected in each country, carrying significant legal and financial penalties for non-compliance. These laws directly impact the organization's ability to operate legally and maintain customer trust internationally.

DInformation security resources available in each country in which the organization operates

Resource availability is a practical consideration for implementing security but doesn't define the *legal mandate* for protecting customer information.

Concept tested: International data privacy regulations

Topics

#Data Privacy#International Compliance#Regulatory Risk#Customer Data Protection

Community Discussion

No community discussion yet for this question.

Full CISM Practice