A company needs to comply with regulations that protect personal data of EU citizens. Which TWO compliance frameworks are directly relevant to this requirement? (Choose two.)
Trap 1: PCI DSS
PCI DSS is specific to payment card data protection, not EU personal data protection.
Trap 2: NIST Cybersecurity Framework
NIST CSF is a US-based cybersecurity framework; it is not directly relevant to EU personal data protection.
Trap 3: HIPAA
HIPAA applies to health data in the US, not to general EU personal data.
- A
PCI DSS
Why wrong: PCI DSS is specific to payment card data protection, not EU personal data protection.
- B
GDPR
GDPR is the primary EU regulation for protecting personal data of EU citizens; it is directly relevant.
- C
ISO 27001
ISO 27001 is a security management standard that helps organizations meet GDPR requirements for data security and is directly relevant as a compliance framework.
- D
NIST Cybersecurity Framework
Why wrong: NIST CSF is a US-based cybersecurity framework; it is not directly relevant to EU personal data protection.
- E
HIPAA
Why wrong: HIPAA applies to health data in the US, not to general EU personal data.