Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A global organization is mandated to comply with the European Union's General Data Protection Regulation (GDPR). As part of their compliance efforts, they are implementing measures to ensure that personal data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. Which GDPR principle is primarily being addressed here?

  1. AAccountability
  2. BPurpose limitation
  3. CIntegrity and confidentiality
  4. DLawfulness, fairness, and transparency
Show answer & explanation

Correct answer: C. Integrity and confidentiality

The GDPR principle of 'Integrity and confidentiality' (Article 5(1)(f)) specifically states that personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. This directly matches the scenario.

Why the other options are wrong

  • A. Accountability requires data controllers to demonstrate compliance with all GDPR principles, not a specific security measure itself.
  • B. Purpose limitation means data should only be collected for specified, explicit, and legitimate purposes, not its secure processing.
  • D. Lawfulness, fairness, and transparency deals with legal basis and clear communication, not data security measures.

GDPR: Integrity and Confidentiality

One of the seven key principles of the General Data Protection Regulation (GDPR), which mandates that personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

  • Focuses on data security.
  • Protects against unauthorized access, loss, destruction.
  • Requires technical and organizational measures.
  • Article 5(1)(f) of GDPR.

Memory trick: GDPR principles are like the 7 commandments for data.

More Security Concepts questions