A company is auditing the manner in which its European customers' personal information is handled.
Which of the following should the company consult?
Correct Answer: A
GDPR - General Data Protection Regulation is a regulation in EU laws that requires businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states.
ISO (International Organization for Standardization) - An independent, non-governmental organization that develops standards to ensure the quality, safety and efficiency of products, services and systems.
NIST (National Institute of Standards and Technology) - A non-regulatory US government agency created to develop cybersecurity standards, guidelines, best practices, and other resources to meet the needs of U.S. industry, federal agencies and the broader public.
PCI DSS (Payment Card Industry Data Security Standard) - A set of security standards for organizations that handle credit cards from major card schemes.