CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a system for a global enterprise that needs to process and store customer data in various regions, each with unique data residency and privacy regulations. The solution must ensure that data processed in one region strictly adheres to that region's regulations and is not transferred or stored elsewhere without explicit compliance. Which architectural principle is MOST critical to implement?
- AClient-side encryption with a global key management system (KMS).
- BData localization (data residency) by design.
- CCentralized data lake with virtual private network (VPN) access.
- DHomomorphic encryption for all data.
Show answer & explanationAnswer & explanation
Correct answer: B. Data localization (data residency) by design.
Data localization (or data residency) by design is the most critical principle here. It ensures that data is stored and processed within specific geographical boundaries to comply with local laws and regulations, directly addressing the requirement for regional compliance and preventing unauthorized cross-border transfers.
Why the other options are wrong
- A. While client-side encryption protects data confidentiality, a global KMS might not align with regional key management requirements, and it doesn't inherently enforce where the encrypted data itself is stored.
- C. A centralized data lake contradicts the requirement for regional data storage and could lead to compliance violations if data from one region is stored in another.
- D. Homomorphic encryption allows computation on encrypted data but doesn't inherently enforce data residency or prevent data from being stored in non-compliant regions.
Data Localization (Data Residency)
Data localization, also known as data residency, is the practice of storing and processing data within specific geographical boundaries (e.g., a country or region) to comply with local laws, regulations, and privacy requirements.
- Mandated by various regulations (e.g., GDPR, CCPA, specific national laws).
- Ensures data remains within a jurisdiction's legal framework.
- Impacts architectural decisions for storage, processing, and disaster recovery.
- Requires careful planning for multi-region deployments.
Memory trick: Local laws, local data: keep it where it's born.