CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security engineer is conducting a security audit of an application running on a public cloud provider. During the audit, they discover that an S3 bucket containing application logs is configured with a public read/write ACL, allowing anonymous users to upload and download files. This directly violates the company's data privacy and security policies. Which compliance standard or framework is MOST directly violated by this configuration?
- AGDPR (General Data Protection Regulation)
- BNIST Cybersecurity Framework
- CISO 27001
- DPCI DSS (Payment Card Industry Data Security Standard)
Show answer & explanationAnswer & explanation
Correct answer: A. GDPR (General Data Protection Regulation)
GDPR specifically mandates strong protection for personal data, including requirements for data integrity, confidentiality, and access control. A publicly exposed S3 bucket with read/write access for logs, which may contain PII, directly violates GDPR's principles of data protection by design and default, and the requirements for data breach prevention.
Why the other options are wrong
- B. NIST Cybersecurity Framework provides guidance for managing cybersecurity risk but is not a regulatory compliance standard that dictates specific punishments for data exposure like GDPR.
- C. ISO 27001 is a broad information security management system (ISMS) standard. While a public S3 bucket would violate controls within ISO 27001, GDPR is more directly punitive regarding personal data exposure.
- D. PCI DSS applies specifically to organizations processing credit card data. While a publicly exposed bucket is a security risk, it only violates PCI DSS if the logs specifically contain cardholder data; GDPR's scope is broader to all personal data.
GDPR Data Protection Principles
A set of principles under GDPR that govern the processing of personal data, emphasizing data protection by design and default.
- Lawfulness, fairness, and transparency.
- Purpose limitation, data minimization.
- Accuracy, storage limitation, integrity, and confidentiality.
Memory trick: Public PII means GDPR is very mad.