CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A global technology company is expanding its operations into new markets. The legal team is concerned about varying data residency and privacy regulations across different jurisdictions, specifically regarding the storage and processing of customer data. They want to implement a strategy that allows them to meet local compliance requirements without having to redesign their entire data architecture for each country. Which compliance strategy is most appropriate for this scenario?

  1. AHarmonized Compliance
  2. BCompliance by Exception
  3. CDecentralized Compliance
  4. DCentralized Compliance
Show answer & explanation

Correct answer: A. Harmonized Compliance

Harmonized compliance aims to identify common requirements across multiple regulations and implement a single set of controls that satisfies the strictest of these, thereby meeting all relevant compliance obligations efficiently without complete redesigns.

Why the other options are wrong

  • B. Compliance by Exception means only addressing regulations when a specific issue arises, which is reactive and risky.
  • C. Decentralized Compliance would require separate data architectures for each country, which the company explicitly wants to avoid.
  • D. Centralized Compliance might struggle with the nuances of local data residency, potentially leading to non-compliance.

Harmonized Compliance

A strategy where an organization identifies common requirements across multiple compliance regulations and implements a unified set of controls that satisfies the most stringent of these, reducing redundant efforts.

  • Identifies commonalities across regulations.
  • Applies the strictest common control.
  • Reduces complexity and cost of compliance.

Memory trick: Harmonize to simplify, satisfy all laws at once.

More Governance, Risk and Compliance questions