ISFS · Question #47
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
The correct answer is D. Personal data protection legislation. Personal data protection legislation (D) is the correct answer because it represents actual laws and regulations enacted by governments - such as GDPR, HIPAA, or CCPA - that carry legal force and can be mandated upon any organization that handles personal data, regardless of…
Question
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
Options
- AISO/IEC 27001:2005
- BIntellectual Property Rights
- CISO/IEC 27002:2005
- DPersonal data protection legislation
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C19% (5)
- D70% (19)
Explanation
Personal data protection legislation (D) is the correct answer because it represents actual laws and regulations enacted by governments - such as GDPR, HIPAA, or CCPA - that carry legal force and can be mandated upon any organization that handles personal data, regardless of size or sector.
Why the distractors are wrong:
- A (ISO/IEC 27001:2005) and C (ISO/IEC 27002:2005) are voluntary international standards - frameworks organizations choose to adopt for best practices, not laws imposed by a governing authority.
- B (Intellectual Property Rights) is a broad legal concept covering copyrights, trademarks, and patents, but it is not specifically an information security legislative act imposed on all organizations.
Memory tip: The key phrase in the question is "legislative or regulatory act...imposed upon" - think enforcement. Only actual laws (like data protection acts) can be imposed. Standards like ISO are chosen, not mandated.
Topics
Community Discussion
No community discussion yet for this question.