CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A security architect is designing a new cloud-native application that will host customer data across multiple regions to ensure global availability and low latency. Due to strict data residency regulations in specific countries, certain customer data must be physically stored and processed only within the geographic boundaries of those countries. Which architectural principle must be applied to meet these regulatory requirements?
- AData Localization (Data Residency)
- BData Masking
- CData Minimization
- DData Tokenization
Show answer & explanationAnswer & explanation
Correct answer: A. Data Localization (Data Residency)
Data localization, also known as data residency, is the principle that certain types of data must be stored and processed within the physical borders of a specific country or jurisdiction. This directly addresses the requirement to comply with regulations that mandate data to remain within particular geographic boundaries.
Why the other options are wrong
- B. Data masking obscures sensitive data for non-production environments but doesn't address where the actual data is stored.
- C. Data minimization involves collecting only necessary data but doesn't dictate its physical storage location.
- D. Data tokenization replaces sensitive data with non-sensitive substitutes but doesn't control the physical location of the original data.
Data Localization (Data Residency)
A regulatory requirement or architectural principle that dictates certain data must be stored and/or processed within the geographic borders of a specific country or jurisdiction.
- Mandated by specific country-level regulations (e.g., GDPR, local laws).
- Requires physical storage and processing within defined borders.
- Impacts cloud deployment strategies and data transfer policies.
- Ensures compliance with local legal frameworks.
Memory trick: Data Localization is like keeping your country's data locked within its own borders.