Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A global technology company is expanding its operations into new countries, each with unique data protection laws (e.g., GDPR in Europe, CCPA in California, LGPD in Brazil). The legal and compliance team is tasked with ensuring that the company's data handling practices, consent mechanisms, and cross-border data transfers adhere to all applicable regulations in every region it operates. Which security concept is this team primarily addressing?

  1. ASecurity Laws and Regulations
  2. BSecurity Frameworks
  3. CSecurity Best Practices
  4. DSecurity Metrics
Show answer & explanation

Correct answer: A. Security Laws and Regulations

The scenario explicitly mentions adherence to 'unique data protection laws' and 'all applicable regulations', directly pointing to the concept of managing security based on legal and regulatory requirements.

Why the other options are wrong

  • B. Security frameworks provide a structured approach to security, but the core issue here is compliance with specific laws.
  • C. Security best practices are general recommendations, not specific legal mandates.
  • D. Security metrics measure performance, not the legal requirements themselves.

Security Laws & Regulations

Mandatory legal requirements established by governmental bodies or industry associations that dictate how organizations must protect data and systems.

  • Non-compliance can lead to severe penalties.
  • Often dictate data privacy, breach notification, and security controls.
  • Vary significantly by geography and industry.

Memory trick: Laws and Regulations are the rules from above, binding our security with governmental love.

More Security Concepts questions