ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy
A global manufacturing company is expanding its operations into a new region. Before establishing local data centers and IT infrastructure, the security team is tasked with understanding the local data protection laws, industry-specific regulations, and international agreements that will apply to their new operations. What is the primary area of security and risk management this activity falls under?
- ASecurity awareness, training, and education
- BThreat modeling concepts and methodologies
- CCompliance requirements
- DRisk management concepts
Show answer & explanationAnswer & explanation
Correct answer: C. Compliance requirements
The scenario directly describes the need to understand 'local data protection laws, industry-specific regulations, and international agreements,' which are all components of compliance requirements. This activity ensures the organization adheres to legal and regulatory obligations.
Why the other options are wrong
- A. Security awareness, training, and education focuses on personnel, not legal frameworks.
- B. Threat modeling focuses on identifying potential threats to a system, not on legal obligations.
- D. Risk management concepts involve identifying, assessing, and mitigating risks, but understanding laws is a prerequisite for compliance, not risk management itself.
Compliance Requirements
The obligations an organization must meet to adhere to applicable laws, regulations, standards, and internal policies.
- Includes legal, regulatory, and contractual obligations.
- Non-compliance can lead to fines, legal action, and reputational damage.
- Requires continuous monitoring and updates to stay current.
Memory trick: Governance guides us, laws define us, ethics binds us.