ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A global manufacturing company is expanding its operations into a new region. Before establishing local data centers and IT infrastructure, the security team is tasked with understanding the local data protection laws, industry-specific regulations, and international agreements that will apply to their new operations. What is the primary area of security and risk management this activity falls under?

  1. ASecurity awareness, training, and education
  2. BThreat modeling concepts and methodologies
  3. CCompliance requirements
  4. DRisk management concepts
Show answer & explanation

Correct answer: C. Compliance requirements

The scenario directly describes the need to understand 'local data protection laws, industry-specific regulations, and international agreements,' which are all components of compliance requirements. This activity ensures the organization adheres to legal and regulatory obligations.

Why the other options are wrong

  • A. Security awareness, training, and education focuses on personnel, not legal frameworks.
  • B. Threat modeling focuses on identifying potential threats to a system, not on legal obligations.
  • D. Risk management concepts involve identifying, assessing, and mitigating risks, but understanding laws is a prerequisite for compliance, not risk management itself.

Compliance Requirements

The obligations an organization must meet to adhere to applicable laws, regulations, standards, and internal policies.

  • Includes legal, regulatory, and contractual obligations.
  • Non-compliance can lead to fines, legal action, and reputational damage.
  • Requires continuous monitoring and updates to stay current.

Memory trick: Governance guides us, laws define us, ethics binds us.

More Security and Risk Management questions