CISM Information Security Governance Practice Question
Which TWO regulations are MOST likely to impact an organization that processes credit card payments and handles personal data of EU residents?
⚠ Common exam trap
The trap is that candidates might select CCPA instead of GDPR because both are privacy regulations, but the question specifies EU residents, making GDPR the correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GDPR
Option C (GDPR) is correct because the organization handles personal data of EU residents, and the EU General Data Protection Regulation imposes requirements on any entity processing that data regardless of where the organization is located, covering lawful processing, data subject rights, breach notification, and cross-border transfers. Option E (PCI DSS) is correct because the organization processes credit card payments, and the Payment Card Industry Data Security Standard mandates controls for protecting cardholder data, including encryption, access control, and network segmentation. Option A (HIPAA) does not apply because it governs protected health information in the US healthcare context, which is not described here. Option B (SOX) does not apply because it concerns financial reporting and internal controls for publicly traded US companies, not payment card or EU personal data. Option D (CCPA) is not the best fit because it addresses California consumers' personal information, whereas the scenario specifically involves EU residents, making GDPR the relevant privacy regulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HIPAA
Why it's wrong here
HIPAA governs protected health information held by US healthcare entities, so it does not address card payment data or EU residents' personal data. It is tempting because it is a well-known privacy regulation, but it would be correct only for an organisation handling medical records rather than payments.
- ✗
SOX
Why it's wrong here
SOX mandates financial reporting controls for US-listed companies, so it does not regulate card payment processing or EU personal data. It is tempting as a recognised compliance framework, but it would be the right answer only where the scenario concerned public-company financial disclosures and audit controls.
- ✓
GDPR
Why this is correct
GDPR governs the processing of EU residents' personal data, imposing lawful-basis, breach-notification and data-subject rights obligations. Because the organisation handles such data, GDPR applies directly, satisfying the stem's EU personal-data constraint alongside the separate payment card regime.
- ✗
CCPA
Why it's wrong here
CCPA grants rights to California residents over their personal information, so it does not cover EU residents or card payment data. It is tempting as a comparable privacy law, but it would be correct only where the organisation handled personal data of California consumers rather than EU data subjects.
- ✓
PCI DSS
Why this is correct
PCI DSS is mandatory for any entity storing, processing or transmitting cardholder data, so it directly governs the credit card payment processing described. It imposes prescriptive controls — encryption, access restriction, logging — that the organisation must evidence during annual assessments, making it one of the two most likely regulatory impacts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.