An organization is migrating its sensitive customer data to a new cloud service provider. The cloud provider operates data centers in multiple jurisdictions, some of which have different data residency and privacy regulations than the organization's home country. The CRISC professional's primary concern is to ensure continuous compliance with all applicable data protection laws. What is the MOST critical governance consideration in this scenario?
- AEnsuring the cloud provider has ISO 27001 certification.
- BConducting regular penetration testing against the cloud environment.
- CEstablishing contractual agreements that mandate compliance with all relevant data protection laws in all jurisdictions where data is processed or stored.
- DImplementing strong encryption for all data both in transit and at rest.
Show answer & explanationAnswer & explanation
Correct answer: C. Establishing contractual agreements that mandate compliance with all relevant data protection laws in all jurisdictions where data is processed or stored.
While encryption and certifications are important technical and assurance controls, the most critical governance consideration for cross-jurisdictional data protection lies in the legal and contractual obligations. Mandating compliance through contracts ensures accountability and enforceability across different regulatory landscapes, directly addressing the primary concern of continuous compliance.
Why the other options are wrong
- A. ISO 27001 is a good security standard, but it doesn't automatically guarantee compliance with specific data residency or privacy laws across multiple jurisdictions.
- B. Penetration testing verifies security posture but does not, by itself, establish or enforce compliance with cross-jurisdictional data residency and privacy regulations.
- D. Encryption is a vital technical control for data security and privacy, but it is a control, not the overarching governance mechanism for ensuring legal compliance across jurisdictions.
Cross-Jurisdictional Data Protection
Ensuring compliance with diverse data privacy and residency laws when data is stored or processed across multiple geographic locations.
- Requires understanding of multiple legal frameworks.
- Contractual agreements are key for third-party accountability.
- Technical controls support, but don't replace, legal compliance.
Memory trick: Think 'Global Data, Local Rules': Contracts are your passport for legal travel.