An organization is implementing a security policy to protect sensitive data. Which three are considered compliance frameworks that could guide this effort? (Choose three.)
Trap 1: NIST Cybersecurity Framework
It is a framework, not a compliance regulation.
Trap 2: ISO 27001
It is a standard, not a compliance framework per se.
- A
NIST Cybersecurity Framework
Why it fails: It is a framework, not a compliance regulation.
- B
ISO 27001
Why it fails: It is a standard, not a compliance framework per se.
- C
HIPAA
HIPAA is a US federal law mandating administrative, physical and technical safeguards for protected health information, so it qualifies as a compliance framework guiding a sensitive-data security policy. It applies specifically to covered entities and business associates handling medical records, distinguishing it from purely technical controls.
- D
PCI DSS
PCI DSS is a mandatory standard governing organisations that store, process or transmit cardholder data, making it a compliance framework for protecting sensitive information. Its twelve requirement families cover network security, encryption, access control and monitoring, giving prescriptive guidance that a security policy can directly adopt.
- E
GDPR
GDPR is an EU regulation imposing lawful-processing, data-minimisation and breach-notification duties on organisations handling personal data of EU residents, so it functions as a compliance framework. Its extraterritorial scope means it can bind the organisation regardless of location, shaping policy for sensitive personal information.