ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy

A multinational corporation is considering processing sensitive customer data in a cloud environment. Before migrating any data, the legal department conducts a thorough review of the cloud provider's data handling practices, security controls, and contractual agreements to ensure they align with the General Data Protection Regulation (GDPR) and other applicable regional data protection laws. What key aspect of security principles is the legal department primarily focusing on?

  1. ASecurity Awareness Training
  2. BIncident Response
  3. CCompliance
  4. DBusiness Continuity
Show answer & explanation

Correct answer: C. Compliance

The legal department's review of the cloud provider's practices against GDPR and other data protection laws directly relates to ensuring the organization's adherence to relevant legal and regulatory requirements. This adherence is defined as compliance.

Why the other options are wrong

  • A. Security awareness training educates employees, which is different from legal and regulatory adherence.
  • B. Incident response deals with handling security breaches after they occur, not pre-migration legal adherence.
  • D. Business continuity focuses on maintaining operations during disruptions, not adherence to legal regulations.

Compliance

The act of adhering to laws, regulations, standards, and policies relevant to an organization's operations.

  • Often involves legal and regulatory requirements.
  • Can result in penalties for non-adherence.
  • Requires continuous monitoring and auditing.

Memory trick: COMPLY with rules, or you'll pay a fine!

More Security Principles questions