ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityHard

A multinational corporation operates in several jurisdictions, each with distinct data privacy regulations (e.g., GDPR, CCPA). The company stores customer Personally Identifiable Information (PII) in a central data lake. To ensure compliance across all regions, which of the following data handling requirements is MOST critical to implement for this PII?

  1. AUniform data retention periods for all PII.
  2. BConsistent data marking and labeling standards.
  3. CAutomated data anonymization processes.
  4. DCentralized data access request portal.
Show answer & explanation

Correct answer: B. Consistent data marking and labeling standards.

Consistent data marking and labeling standards are crucial because they enable the organization to accurately identify the sensitivity, regulatory requirements, and ownership of specific PII, regardless of its location or the specific jurisdiction. This foundational step allows for the correct application of all other controls, including retention, access, and anonymization, in a complex multi-jurisdictional environment. Without consistent labels, applying appropriate controls becomes haphazard and prone to non-compliance.

Why the other options are wrong

  • A. Uniform retention periods are often impractical and non-compliant in multi-jurisdictional contexts, as regulations vary. Tailored retention based on classification/labeling is usually required.
  • C. Automated anonymization is a control for specific data types and uses, but it depends on correctly identifying and classifying the data first, which marking/labeling enables.
  • D. A centralized access request portal is important for user rights but doesn't address the fundamental challenge of identifying *which* PII is subject to *which* regulations.

Data Marking & Labeling

The process of applying visual or electronic indicators to data to denote its classification, sensitivity, handling requirements, and regulatory obligations, facilitating consistent protection across an organization.

  • Crucial for communicating data's value and handling rules to users and systems.
  • Enables automated enforcement of security controls.
  • Must be consistently applied across all data storage and processing environments.

Memory trick: Label data first, then rules can last.

More Asset Security questions