CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A global healthcare provider is deploying a new patient management system across multiple countries. Due to varied and strict data privacy regulations (e.g., GDPR in Europe, HIPAA in the US, local laws in Asia), the architecture must ensure that patient data collected in a specific region remains stored and processed exclusively within that region's geographical boundaries. Which architectural principle directly addresses this requirement?

  1. AData Redundancy
  2. BData Minimization
  3. CData Localization (Data Residency)
  4. DData Obfuscation
Show answer & explanation

Correct answer: C. Data Localization (Data Residency)

Data Localization, also known as Data Residency, is the architectural principle that mandates sensitive data to be stored and processed within specific geographical boundaries to comply with local laws and regulations. This directly addresses the requirement for patient data to remain within its region of origin.

Why the other options are wrong

  • A. Data Redundancy is about duplicating data for availability and disaster recovery, not about restricting its geographical storage location.
  • B. Data Minimization focuses on collecting and processing only the necessary data, not on its geographical storage location.
  • D. Data Obfuscation involves making data unintelligible (e.g., masking, encryption) but does not dictate its physical storage location.

Data Localization (Data Residency)

The requirement that certain data must be stored and processed within the geographical borders of a specific country or region, often due to legal or regulatory mandates.

  • Ensures compliance with national data protection laws.
  • Impacts cloud deployment strategies and data transfer mechanisms.
  • Requires careful planning for global applications and services.

Memory trick: Data security principles are like 'rules for data travelers', some can go anywhere, some must stay home.

More Security Architecture questions