CISSP · Question #1008
Why would a system be structured to isolate different classes of information from one another and segregate them by user jurisdiction?
The correct answer is C. The organization can vary its system policies to comply with conflicting national laws. Isolating information classes by user jurisdiction is a data sovereignty and compliance strategy that allows organizations to apply different legal and regulatory policies to data based on geographic or national boundaries.
Question
Why would a system be structured to isolate different classes of information from one another and segregate them by user jurisdiction?
Options
- AThe organization can avoid e-discovery processes in the event of litigation.
- BThe organization's infrastructure is clearly arranged and scope of responsibility is simplified.
- CThe organization can vary its system policies to comply with conflicting national laws.
- DThe organization is required to provide different services to various third-party organizations.
How the community answered
(50 responses)- A18% (9)
- B4% (2)
- C70% (35)
- D8% (4)
Why each option
Isolating information classes by user jurisdiction is a data sovereignty and compliance strategy that allows organizations to apply different legal and regulatory policies to data based on geographic or national boundaries.
Isolation by jurisdiction does not enable avoidance of e-discovery, as courts can still compel production of relevant data regardless of how it is segmented, and attempting to evade e-discovery through data structuring could itself be sanctionable.
While segmentation may offer some organizational clarity, simplified scope of responsibility is a secondary operational benefit and not the primary architectural reason for isolating data by user jurisdiction.
Different nations have conflicting data protection, privacy, and security laws (e.g., GDPR in the EU vs. CCPA in the US vs. China's PIPL), and by isolating data by user jurisdiction, an organization can apply the appropriate national policy to each data class without violating laws in other regions. This architectural approach, often called data sovereignty or jurisdictional segmentation, ensures that processing, storage, and access controls can be tailored to meet the specific legal requirements of each applicable jurisdiction. Without this isolation, a single uniform policy might simultaneously comply with one nation's law while violating another's.
Providing different services to third-party organizations relates to service-level or contractual segmentation, not to the legal and regulatory rationale of separating data by national jurisdiction.
Concept tested: Data sovereignty and jurisdictional compliance segmentation
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-data-classification-and-protection
Topics
Community Discussion
No community discussion yet for this question.