350-201 Question 18
Select 2A financial institution is implementing a system to ensure compliance with industry-specific regulatory standards. Which of the following compliance standards would most likely apply to this organization?
- A
PCI DSS (Payment Card Industry Data Security Standard)
- B
FISMA (Federal Information Security Management Act)
- C
SOX (Sarbanes-Oxley Act)
- D
GDPR (General Data Protection Regulation)
- E
FedRAMP (Federal Risk and Authorization Management Program)
Show answer and explanation
Correct answers: A, C
Explanation
Financial institutions are subject to industry-specific compliance standards such as PCI DSS, which governs payment card security, and SOX, which enforces financial reporting and auditing requirements for public companies. These standards are critical for ensuring the security and integrity of financial data, which is a core concern in the financial sector.
- A. Correct.
PCI DSS is applicable to organizations that handle payment card information, such as financial institutions, making it relevant in this scenario.
- B. Incorrect.
FISMA applies to federal agencies and their contractors, not directly to financial institutions unless they are working with the federal government.
- C. Correct.
SOX applies to public companies, particularly in financial reporting and auditing, and is relevant to financial institutions.
- D. Incorrect.
GDPR primarily governs data privacy for entities operating in or dealing with the personal data of EU citizens. While important, it is not specific to financial institutions in this scenario.
- E. Incorrect.
FedRAMP is focused on cloud service providers working with federal agencies and is not directly related to financial institutions.