Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A multinational corporation is developing a new global data privacy policy. They must ensure compliance with GDPR in Europe, CCPA in California, and various other regional regulations. Which aspect of security governance is primarily addressed by this effort?
- ASecurity Operations
- BRisk Management
- CLegal and Regulatory Compliance
- DSecurity Policies
Show answer & explanationAnswer & explanation
Correct answer: C. Legal and Regulatory Compliance
The effort to comply with GDPR, CCPA, and other regional regulations directly falls under legal and regulatory compliance. This involves understanding and adhering to external laws and standards applicable to the organization's data handling.
Why the other options are wrong
- A. Security operations involve the day-to-day activities of managing security, which is a result of policies, not the policy creation itself.
- B. Risk management involves identifying, assessing, and mitigating risks, which is related but not the primary focus of creating a policy to meet legal requirements.
- D. Security policies are the documents themselves, but the *reason* for their specific content in this scenario is compliance.
Legal & Regulatory Compliance
The process of ensuring an organization adheres to external laws, regulations, and industry standards relevant to its operations.
- Mandatory adherence to external rules.
- Examples include GDPR, HIPAA, PCI DSS.
- Often drives the creation and enforcement of internal security policies.
Memory trick: Governance is the 'GO' for 'Organizational' security 'VE'hicle's 'RN'ules and 'ANCE'stry.