Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A global company is expanding its operations into new regions and must comply with various international data privacy regulations, including GDPR and CCPA. The legal team is concerned about data residency requirements, where certain types of data must physically remain within specific geographic borders. Which security program element is primarily responsible for ensuring the company adheres to these complex legal and regulatory mandates?

  1. AVulnerability Management
  2. BGovernance, Risk, and Compliance (GRC)
  3. CSecurity Architecture
  4. DIncident Response Planning
Show answer & explanation

Correct answer: B. Governance, Risk, and Compliance (GRC)

Governance, Risk, and Compliance (GRC) is the overarching program that ensures an organization meets its objectives by effectively managing risks, ensuring compliance with relevant laws and regulations (like GDPR and CCPA), and adhering to internal policies. Data residency requirements fall directly under the compliance aspect of GRC.

Why the other options are wrong

  • A. Vulnerability management focuses on identifying and fixing weaknesses, not on legal and regulatory adherence.
  • C. Security architecture designs secure systems, but GRC sets the requirements for that design based on regulations.
  • D. Incident response focuses on handling security breaches, not establishing compliance with regulations.

Governance, Risk, and Compliance (GRC)

A comprehensive approach to managing an organization's overall governance, enterprise risk management, and compliance with regulations.

  • Integrates various aspects of organizational management.
  • Helps achieve objectives while managing risks and adhering to laws.
  • Critical for complex regulatory environments.

Memory trick: GRC: The company's 'GPS' for laws, risks, and good practice.

More Security Concepts questions