350-201 Question 20
Select 3A company is preparing to implement a compliance program to meet regulatory requirements. The company processes payment card transactions, stores personal customer data, and is expanding its services to Europe. Which compliance standards should the company focus on to meet industry-specific and regional requirements?
- A
PCI DSS
- B
GDPR
- C
FedRAMP
- D
SOX
- E
ISO 27001
Show answer and explanation
Correct answers: A, B, E
Explanation
The company processes payment card transactions, so PCI DSS compliance is mandatory to secure cardholder data. Since the company is expanding its services to Europe and stores personal customer data, GDPR compliance is also essential to meet EU data privacy regulations. Additionally, ISO 27001 is an important standard for establishing best practices in information security management, making it a valuable framework for the company's cybersecurity strategy.
- A. Correct.
PCI DSS is a compliance standard specifically designed for companies that handle payment card transactions. It is relevant for ensuring the security of credit card data.
- B. Correct.
GDPR is the General Data Protection Regulation and is mandatory for companies that process or store personal data of residents in the European Union, regardless of the company's location.
- C. Incorrect.
FedRAMP is specific to cloud service providers working with U.S. federal agencies and is not applicable in this scenario.
- D. Incorrect.
SOX (Sarbanes-Oxley Act) is primarily focused on financial reporting and corporate governance for publicly traded companies, which is not directly related to the scenario.
- E. Correct.
ISO 27001 is an international standard for information security management systems (ISMS) and is highly relevant for companies aiming to establish a robust cybersecurity program.