712-50 Question 40
Single answerA multinational retail company based in Germany is acquiring a smaller U.S. e-commerce firm. The parent company processes EU customer data, uses payment cards globally, and plans to integrate the acquired firm's customer analytics platform. During due diligence, the CEO asks the CISO for the MOST appropriate first step to ensure the combined organization aligns its security program with applicable external obligations and organizational ethics. Which action should the CISO take FIRST?
- A
Adopt ISO/IEC 27001 certification across both companies immediately, because certification will automatically satisfy legal and regulatory obligations
- B
Conduct a formal obligations and ethics mapping exercise to identify applicable laws, regulations, contractual requirements, standards, and internal ethical commitments before defining integration controls
- C
Prioritize the U.S. company's controls against the NIST Cybersecurity Framework and defer legal review until after technical gaps are remediated
- D
Apply the stricter of GDPR or U.S. state privacy laws uniformly to all systems and data, because using the highest standard eliminates compliance risk
Show answer and explanation
Correct answer: B
Explanation
The best answer is to conduct a formal obligations and ethics mapping exercise before designing the integrated security program. A CCISO is expected to understand that external obligations come from multiple sources: laws and regulations such as the EU General Data Protection Regulation (GDPR), U.S. state privacy and breach notification laws, and possibly employment or consumer protection laws; contractual and industry requirements such as PCI DSS for cardholder data environments; and voluntary standards or best practices such as ISO/IEC 27001 or the NIST Cybersecurity Framework. These are not interchangeable. Laws and regulations are mandatory where applicable, PCI DSS is typically contractually binding through payment brands and acquiring banks, and standards such as ISO 27001 or NIST CSF help structure controls but do not independently determine legal compliance. For an acquisition, the CISO should first establish a compliance universe or obligations register, map those obligations to business processes, systems, data flows, jurisdictions, and ethical commitments, and then select or harmonize controls. This approach reflects sound governance practice and aligns with common expectations in ISO/IEC 27001 for understanding organizational context and compliance obligations, as well as privacy accountability principles under GDPR Articles 5 and 24.
- A. Incorrect.
This is incorrect because ISO/IEC 27001 is a voluntary information security management standard, not a substitute for legal or regulatory compliance. Certification can support governance and risk management, but it does not automatically satisfy obligations under laws such as the GDPR, payment card contractual requirements such as PCI DSS, labor laws, breach notification rules, or sector-specific regulations. A common misconception is treating certification as a blanket compliance solution; in reality, legal applicability must be determined separately and then translated into policy and control requirements.
- B. Correct.
This is correct because the most appropriate first step is to determine what external and internal obligations apply before selecting or harmonizing controls. In this scenario, the organization likely faces GDPR requirements for EU personal data, PCI DSS obligations tied to payment card processing, U.S. state privacy and breach notification laws, contractual obligations with partners and processors, and internal ethical commitments regarding customer data use. A formal mapping exercise establishes scope, identifies overlaps and conflicts, supports risk-based prioritization, and provides defensible governance decisions during post-acquisition integration.
- C. Incorrect.
This is incorrect because although the NIST Cybersecurity Framework is a useful best-practice framework for improving cybersecurity posture, beginning technical remediation before understanding legal, regulatory, and contractual obligations can cause the organization to miss mandatory requirements or misprioritize resources. The misconception here is assuming that security framework alignment should precede compliance scoping. For a CISO at the executive level, obligation identification and governance alignment come first so that any framework adoption is informed by what must be achieved.
- D. Incorrect.
This is incorrect because applying the strictest rule globally may appear conservative, but it is not automatically the most appropriate first action and may create unnecessary operational burden, legal misalignment, or over-collection of controls that do not address the actual obligation set. Different laws apply based on data subjects, processing activities, jurisdictions, and business arrangements. In addition, organizational ethics may require more nuanced decisions than simply choosing the harshest legal baseline. The misconception is that 'highest standard everywhere' removes compliance risk; in practice, compliance depends on applicability, lawful basis, contractual terms, and governance.