ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A multinational corporation operates in various countries, each with its own data protection laws, such as GDPR in Europe and CCPA in California. The corporation must adapt its data handling practices to meet the specific requirements of each region. Which aspect of security principles is this scenario primarily focused on?
- ASecurity Awareness Training
- BCompliance
- CBusiness Continuity
- DRisk Treatment
Show answer & explanationAnswer & explanation
Correct answer: B. Compliance
The need to adapt data handling practices to meet specific data protection laws like GDPR and CCPA directly relates to ensuring compliance with legal and regulatory requirements.
Why the other options are wrong
- A. Security awareness training educates employees, but doesn't directly address adapting to specific legal frameworks.
- C. Business continuity focuses on maintaining essential business functions during and after disruptions.
- D. Risk treatment involves deciding how to handle identified risks (e.g., mitigate, accept, transfer).
Compliance
The act of adhering to laws, regulations, standards, and policies relevant to an organization's operations and data handling.
- Involves meeting legal, regulatory, and industry requirements.
- Non-compliance can lead to fines, legal action, and reputational damage.
- Requires continuous monitoring and adaptation to changing mandates.
Memory trick: Policy is the rulebook, Standards are the specifics, Guidelines are helpful hints, and Compliance is following them all.