A compliance officer is responsible for selecting the right governance framework to protect individuals' data.
Which of the following is the appropriate framework for the company to consult when collecting international user data for the purpose of processing credit cards?
Correct Answer: D
PCI DSS (Payment Card Industry Data Security Standard) is the most appropriate governance framework when collecting and processing credit card data, including international user data. PCI DSS establishes security standards for organizations that handle payment card transactions and ensures the protection of cardholder data globally. The other options, such as ISO 27001 and NIST 800-53, provide general security frameworks, but PCI DSS is specifically designed for payment card security, which is critical when handling credit card information. CASP+ emphasizes the role of PCI DSS in ensuring the secure handling of payment data.
References:
* CASP+ CAS-004 Exam Objectives: Domain 1.0 - Risk Management (PCI DSS Compliance for Payment Systems)
* CompTIA CASP+ Study Guide: Payment Systems Security and PCI DSS