Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A global technology company is expanding its operations into new countries, each with unique data residency and privacy laws. The company's security team must ensure that their data handling practices comply with all applicable regulations worldwide. Which aspect of security governance is most critical in this scenario?

  1. ASecurity metrics reporting
  2. BLegal and regulatory compliance
  3. CIncident response plan maturity
  4. DSecurity awareness training effectiveness
Show answer & explanation

Correct answer: B. Legal and regulatory compliance

The scenario explicitly states the need to comply with 'unique data residency and privacy laws' and 'all applicable regulations worldwide'. This directly falls under legal and regulatory compliance, a key aspect of security governance.

Why the other options are wrong

  • A. Metrics report on security performance, not directly address regulatory adherence.
  • C. Incident response deals with breaches, not the initial compliance with laws for data handling.
  • D. Training effectiveness is about employee behavior, not the legal framework itself.

Legal & Regulatory Compliance

The process of ensuring that an organization adheres to all relevant laws, regulations, and industry standards pertaining to information security and data privacy.

  • Non-compliance can lead to significant fines, legal penalties, and reputational damage.
  • Requires continuous monitoring and adaptation to evolving legal landscapes.
  • Examples include GDPR, CCPA, HIPAA, PCI DSS.

Memory trick: Governance ensures policies, risks, and compliance are all in check.

More Security Concepts questions