Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium
A multinational corporation is migrating its human resources data to a public cloud. The data includes personally identifiable information (PII) of employees across various jurisdictions, each with distinct data protection laws. The legal team is concerned about ensuring continuous compliance with these differing regulations. Which of the following approaches is MOST effective for addressing this challenge?
- AOutsourcing legal compliance to the cloud service provider (CSP).
- BApplying the most stringent data protection regulation globally to all data.
- CImplementing a data classification scheme and applying controls based on data residency and jurisdictional requirements.
- DEncrypting all PII at rest and in transit, regardless of its origin.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing a data classification scheme and applying controls based on data residency and jurisdictional requirements.
A data classification scheme, coupled with controls based on residency and jurisdictional requirements, allows for tailored compliance, ensuring that specific regulatory obligations are met for each data set without over-applying controls unnecessarily.
Why the other options are wrong
- A. While CSPs have compliance offerings, ultimate legal responsibility for data protection remains with the customer; outsourcing compliance entirely is not feasible or advisable.
- B. While simplifying, this can lead to unnecessary costs and operational complexities where not required.
- D. Encryption is a fundamental security control but doesn't, by itself, address the nuances of differing legal and regulatory compliance obligations.
Jurisdictional Compliance
Adhering to the specific data protection and privacy laws of multiple geographic regions where data is collected, processed, or stored.
- Laws vary significantly by country/region (e.g., GDPR, CCPA).
- Requires understanding data residency and processing locations.
- Often necessitates granular control strategies for data.
Memory trick: Different lands, different laws; classify and comply, not just encrypt and ignore.