100-160 Question 245
Select 2A cybersecurity team is responding to a data breach in an organization that processes customer credit card information. Which of the following compliance frameworks must they consider when handling the incident to ensure proper legal and regulatory adherence?
- A
PCI DSS (Payment Card Industry Data Security Standard)
- B
GDPR (General Data Protection Regulation)
- C
SOX (Sarbanes-Oxley Act)
- D
HIPAA (Health Insurance Portability and Accountability Act)
- E
COBIT (Control Objectives for Information and Related Technologies)
Show answer and explanation
Correct answers: A, B
Explanation
In this scenario, the cybersecurity team must ensure compliance with frameworks like PCI DSS and GDPR because they handle sensitive customer credit card information and potentially personal data. PCI DSS outlines specific requirements for securing cardholder data, and GDPR applies if personal data of EU citizens is involved. SOX, HIPAA, and COBIT are not directly relevant to this type of incident.
- A. Correct.
PCI DSS is directly applicable since it governs the security of credit card data, which is central to the scenario. Incident handling must comply with PCI DSS requirements.
- B. Correct.
GDPR is relevant if the organization handles the personal data of European Union citizens. Incident handling must follow GDPR's breach notification and data protection requirements.
- C. Incorrect.
SOX focuses on financial reporting and corporate governance. It is not directly connected to handling incidents involving credit card or personal data breaches.
- D. Incorrect.
HIPAA is specific to the healthcare industry and the protection of health-related information. It does not apply to customer credit card information in this case.
- E. Incorrect.
COBIT is a framework for IT governance and management but does not specifically mandate requirements for incident handling or compliance related to data breaches.