CompTIA SecurityX (CAS-005)Security ArchitectureHard
A global organization is implementing a new customer relationship management (CRM) system that will store personally identifiable information (PII) for customers across various jurisdictions, each with different data residency and privacy regulations. The security architect needs to design a data architecture that ensures compliance while optimizing performance. Which approach is MOST suitable for addressing these complex requirements?
- ACentralizing all PII data in a single, highly secured data center in a neutral country.
- BUtilizing a globally distributed database with strong encryption, irrespective of data origin.
- CAnonymizing all PII data before storage and only de-anonymizing for specific authorized processes.
- DImplementing data localization by storing PII within the geographical boundaries of its origin.
Show answer & explanationAnswer & explanation
Correct answer: D. Implementing data localization by storing PII within the geographical boundaries of its origin.
Data localization, or data residency, is the practice of storing data within the geographical borders of its origin. This directly addresses legal and regulatory requirements for data residency and privacy, which vary significantly across jurisdictions, ensuring compliance for PII in a global organization, even if it might add complexity to performance optimization.
Why the other options are wrong
- A. Centralizing data might simplify management but would likely violate data residency laws in many jurisdictions, making it non-compliant for global PII.
- B. While strong encryption is essential, it does not, by itself, satisfy data residency requirements. A globally distributed database without localization could still violate regulations if data is stored outside its legal jurisdiction.
- C. Anonymization is a strong privacy control, but it might not be feasible for a CRM system where identifiable customer interaction is necessary. Furthermore, even anonymized data could be subject to residency requirements if the original PII is still stored elsewhere, or if the anonymized data can be re-identified.
Data Localization (Data Residency)
Data localization, or data residency, is a legal and regulatory requirement that certain types of data must be stored and processed within the geographical boundaries of a specific country or jurisdiction.
- Mandated by various international and national laws (e.g., GDPR, CCPA).
- Ensures compliance with local data protection and privacy regulations.
- Can impact system design, requiring distributed data storage.
- Often requires careful consideration of data flow and processing locations.
Memory trick: Each country's data stays in its own home.