5.4 Summarize elements of effective security compliance

Domain 5: Security Program Management and Oversight

Compliance is about proving the organization meets internal and external obligations, and this objective splits into reporting and monitoring on one side and privacy on the other. Know internal versus external compliance reporting, and the consequences of failure: fines, sanctions, reputational damage, loss of license, and contractual impacts. Monitoring includes due diligence and due care, attestation and acknowledgement, internal and external review, and automation of compliance checks. On privacy, learn the legal implications at local, national, and global levels, and the key vocabulary: data subject, controller versus processor, data ownership, data inventory and retention, and the right to be forgotten. Due care versus due diligence is a perennial trap — diligence is the research and investigation, care is acting reasonably on what you learned. Candidates also conflate compliance with security; the exam expects you to know that meeting a compliance bar is evidence for auditors and regulators, while controls still need to be validated as actually effective. Attestation questions hinge on someone formally asserting that requirements are met.

What you must know

common pitfall · Candidates invert due care and due diligence, forgetting that diligence is investigating obligations while care is acting reasonably on them.

Try a sample question

An online retailer collects personal data from customers in the European Union. The retailer decides what data is collected, why it is collected, and how long it is retained, and it hires a cloud analytics firm to process the data on its behalf. Under privacy regulations such as GDPR, what is the retailer's role?

  • A Data processor
  • B Data custodian
  • C Data subject
  • D Data controller
Show answer & explanations
  • A A data processor handles personal data only on documented instructions from another party; in this scenario the cloud analytics firm, not the retailer, fills that role.
  • B A data custodian is an internal operational role that implements storage, backups, and technical safeguards for data; it is not the legal party that determines processing purposes.
  • C Data subjects are the identifiable individuals whose personal information is collected, meaning the EU customers themselves rather than the organization gathering and using the data.
  • D correct ·Correct. The data controller determines the purposes and means of processing; because the retailer decides what is collected, why, and for how long, it is the controller and carries primary compliance obligations.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 5.4 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free