Courseiva

CISM Information Security Governance Practice Question

Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?

⚠ Common exam trap

The trap is that candidates might select CCPA instead of GDPR because both are privacy regulations, but the question specifies EU residents, making GDPR the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GDPR

Option C (GDPR) is correct because the organization handles personal data of EU residents, and the EU General Data Protection Regulation imposes requirements on any entity processing that data regardless of where the organization is located, covering lawful processing, data subject rights, breach notification, and cross-border transfers. Option E (PCI DSS) is correct because the organization processes credit card payments, and the Payment Card Industry Data Security Standard mandates controls for protecting cardholder data, including encryption, access control, and network segmentation. Option A (HIPAA) does not apply because it governs protected health information in the US healthcare context, which is not described here. Option B (SOX) does not apply because it concerns financial reporting and internal controls for publicly traded US companies, not payment card or EU personal data. Option D (CCPA) is not the best fit because it addresses California consumers' personal information, whereas the scenario specifically involves EU residents, making GDPR the relevant privacy regulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HIPAA

    Why it's wrong here

    HIPAA governs protected health information held by US healthcare entities, so it does not address card payment data or EU residents' personal data. It is tempting because it is a well-known privacy regulation, but it would be correct only for an organisation handling medical records rather than payments.

  • ✗

    SOX

    Why it's wrong here

    SOX mandates financial reporting controls for US-listed companies, so it does not regulate card payment processing or EU personal data. It is tempting as a recognised compliance framework, but it would be the right answer only where the scenario concerned public-company financial disclosures and audit controls.

  • ✓

    GDPR

    Why this is correct

    GDPR governs the processing of EU residents' personal data, imposing lawful-basis, breach-notification and data-subject rights obligations. Because the organisation handles such data, GDPR applies directly, satisfying the stem's EU personal-data constraint alongside the separate payment card regime.

  • ✗

    CCPA

    Why it's wrong here

    CCPA grants rights to California residents over their personal information, so it does not cover EU residents or card payment data. It is tempting as a comparable privacy law, but it would be correct only where the organisation handled personal data of California consumers rather than EU data subjects.

  • ✓

    PCI DSS

    Why this is correct

    PCI DSS is mandatory for any entity storing, processing or transmitting cardholder data, so it directly governs the credit card payment processing described. It imposes prescriptive controls — encryption, access restriction, logging — that the organisation must evidence during annual assessments, making it one of the two most likely regulatory impacts.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.