Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A global pharmaceutical company is undergoing a major divestiture, separating a significant portion of its R&D division into a new entity. This involves disentangling highly sensitive intellectual property (IP), patient data, and regulated systems while ensuring continuous compliance with GxP (Good Practice) regulations and maintaining data integrity. The cybersecurity architect needs to define a GRC technical strategy for securely and compliantly migrating the separated assets. Which strategy is MOST critical to ensure the integrity and auditable transfer of regulated data and IP?

  1. AImplementing a new, isolated network infrastructure for the divested entity.
  2. BDeploying a robust Identity and Access Management (IAM) solution for the new entity.
  3. CConducting comprehensive penetration testing on the new entity's systems post-migration.
  4. DUtilizing cryptographic hashing and digital signatures for all transferred data packages with a verifiable chain of custody.
Show answer & explanation

Correct answer: D. Utilizing cryptographic hashing and digital signatures for all transferred data packages with a verifiable chain of custody.

For regulated data and IP transfer during a divestiture, ensuring data integrity and an auditable chain of custody is paramount for GxP compliance. Cryptographic hashing confirms data hasn't been altered, and digital signatures prove its origin and authenticity. A verifiable chain of custody documents every step of the transfer, satisfying stringent regulatory requirements.

Why the other options are wrong

  • A. While an isolated network is important for the new entity's security, it doesn't directly address the integrity or auditable transfer of the data itself during the migration process.
  • B. IAM is essential for managing access in the new entity, but it doesn't inherently guarantee the integrity or auditable transfer of the data during the physical or logical migration phase.
  • C. Penetration testing verifies security post-migration but doesn't provide the real-time integrity checks or auditable proof of transfer required during the actual data movement for regulated assets.

Cryptographic Integrity for Data Migration

Using cryptographic hashing and digital signatures, combined with a verifiable chain of custody, to ensure the integrity, authenticity, and auditable transfer of sensitive and regulated data during migrations.

  • Hashing verifies data hasn't changed.
  • Digital signatures prove sender identity and message integrity.
  • Chain of custody documents every data handling step.

Memory trick: Divested data needs crypto proofs and a custody chain, no trust without it.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions