Certified Information Security Manager (CISM)Information Security Risk ManagementHard

A global manufacturing company is expanding its operations into a new region with strict data residency and privacy laws. The existing enterprise architecture, which relies on centralized data processing in a different continent, is not compliant with these new regulations. The information security manager is tasked with addressing this compliance gap. Which of the following approaches represents the MOST effective long-term strategy?

  1. AEstablish a separate, localized data center and processing infrastructure within the new region.
  2. BUtilize data anonymization techniques for all sensitive data collected in the new region.
  3. CImplement data encryption for all data transferred to and from the new region.
  4. DPurchase legal insurance to cover potential fines related to non-compliance.
Show answer & explanation

Correct answer: A. Establish a separate, localized data center and processing infrastructure within the new region.

Data residency laws often require that certain data types be physically stored and processed within specific geographical boundaries. Encryption and anonymization may help with privacy but do not typically satisfy strict data residency requirements. Establishing a localized infrastructure directly addresses the physical location mandate, offering the most effective long-term compliance solution.

Why the other options are wrong

  • B. Anonymization reduces privacy risk but doesn't necessarily satisfy data residency laws that mandate physical location.
  • C. Encryption protects data in transit and at rest but does not change its physical location, which is the core of data residency.
  • D. Legal insurance is a risk financing strategy, not a control that addresses the root cause of non-compliance with data residency laws.

Data Residency

The requirement for data to be stored and processed within specific geographic boundaries, often due to legal or regulatory mandates.

  • Driven by national laws and regulations.
  • Impacts cloud computing and global data flows.
  • Requires careful architectural planning.

Memory trick: Data residency: data must sleep where the law lives.

More Information Security Risk Management questions