712-50 Question 39
Single answerA multinational software company headquartered in the EU is acquiring a U.S.-based health analytics firm. The target company processes personal data of EU customers, stores payment card data for subscription billing, and receives protected health information from U.S. healthcare providers. The CEO asks the newly appointed CISO to recommend the MOST effective first step for aligning the combined security program with applicable external obligations and organizational ethics without delaying integration. What should the CISO do FIRST?
- A
Adopt ISO/IEC 27001 as the enterprise security standard and require all business units to certify within 12 months
- B
Commission an enterprise-wide legal, regulatory, contractual, and ethical obligations assessment to map business activities, data types, and jurisdictions to applicable requirements
- C
Immediately standardize controls to meet the strictest known requirement, such as HIPAA Security Rule safeguards, across the entire enterprise
- D
Defer compliance alignment until the post-merger IT architecture is finalized so controls are not designed twice
Show answer and explanation
Correct answer: B
Explanation
The most effective first action is to determine what obligations actually apply before selecting or harmonizing controls. In this scenario, the combined company likely faces overlapping requirements from multiple sources: GDPR for EU personal data processing, HIPAA for U.S. protected health information where applicable, PCI DSS for payment card environments, state breach notification laws, customer contractual security clauses, and potentially sector-specific or cross-border transfer requirements. A CISO operating at the executive level should begin with an obligations mapping exercise that inventories data categories, processing purposes, jurisdictions, third parties, and legal entities, then maps these to mandatory laws and regulations as well as voluntary standards and internal ethical commitments. This is consistent with governance best practice in ISO/IEC 27001 and ISO/IEC 27002, which emphasize understanding organizational context and compliance obligations, as well as with NIST CSF's Govern function and common due diligence practices in M&A. Ethical leadership also requires more than minimum legal compliance; it includes ensuring transparency, proportionality, accountability, and responsible handling of sensitive information during integration.
- A. Incorrect.
This is not the best first step. ISO/IEC 27001 is a useful voluntary standard for establishing an information security management system, but certification alone does not identify all binding legal, regulatory, or contractual obligations. The organization first needs to understand which requirements apply, such as GDPR for EU personal data, HIPAA for protected health information in the U.S., and PCI DSS where payment card data is stored, processed, or transmitted. Selecting a framework before determining applicability can leave gaps or cause misaligned priorities.
- B. Correct.
This is the best answer. In a merger scenario involving multiple jurisdictions and regulated data types, the CISO should first establish a formal obligations assessment. That means identifying what data is handled, where it flows, which entities process it, what contracts impose security obligations, and which laws, regulations, and standards apply in each jurisdiction. This approach supports risk-based governance, enables defensible prioritization, and aligns with ethical expectations of due care, transparency, and accountability. It also prevents the common error of treating one framework or regulation as sufficient for all business operations.
- C. Incorrect.
This is plausible but incorrect as the first step. Applying the strictest requirement universally may seem conservative, but it can be inefficient, legally incomplete, and operationally disruptive. HIPAA applies to covered entities and business associates handling protected health information, but it does not address all obligations related to EU personal data under GDPR or cardholder data under PCI DSS. The misconception is that one stringent regime automatically satisfies all others. In practice, requirements differ in scope, legal basis, reporting, data subject rights, and third-party obligations.
- D. Incorrect.
This is incorrect. Waiting until architecture decisions are complete creates avoidable compliance and ethical risk during integration, especially when sensitive and regulated data is already being processed. Regulatory obligations apply immediately based on processing activities, not only after technical integration is complete. A preliminary obligations assessment can and should occur in parallel with architectural planning so controls, contracts, and governance decisions are informed from the outset.