CISM · Question #393
A financial institution is planning to introduce a new service that requires the handling of customer data. Which of the following is MOST important for the information security manager to determine?
The correct answer is A. Legal and regulatory requirements related to the types of data to be processed. Legal and regulatory requirements (A) must be determined first because they define the non-negotiable baseline - violating data protection laws (GDPR, HIPAA, PCI-DSS, etc.) can result in fines, sanctions, or loss of operating license, making compliance a foundational constraint…
Question
A financial institution is planning to introduce a new service that requires the handling of customer data. Which of the following is MOST important for the information security manager to determine?
Options
- ALegal and regulatory requirements related to the types of data to be processed
- BAdequacy of infrastructure and technical controls to protect customer information
- CRisk and data privacy reporting requirements for the board
- DProject funding availability to support information security needs
How the community answered
(57 responses)- A81% (46)
- B11% (6)
- C2% (1)
- D7% (4)
Explanation
Legal and regulatory requirements (A) must be determined first because they define the non-negotiable baseline - violating data protection laws (GDPR, HIPAA, PCI-DSS, etc.) can result in fines, sanctions, or loss of operating license, making compliance a foundational constraint before any other decisions are made.
Why the distractors fall short:
- B (Infrastructure/technical controls) - important, but you can't design controls without first knowing what compliance obligations apply to the data type.
- C (Board reporting requirements) - a governance concern that follows from knowing the regulatory landscape, not a prerequisite to it.
- D (Project funding) - relevant to project management, but budget questions come after you know what legal obligations must be met.
Memory tip: Think "Law before walls" - you must know the legal requirements before you can build the technical walls to satisfy them. Whenever a question involves a new service handling customer data, regulatory/legal determination always comes first in the security manager's checklist.
Topics
Community Discussion
No community discussion yet for this question.