ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A development team building a SaaS CRM will host EU customer records in a U.S. data center. When identifying compliance requirements, which feature must be captured because it is explicitly mandated by the GDPR rather than by industry or company policy?
Encrypt all stored data using a FIPS 140-2 Level 3 validated hardware security module.
Retain detailed audit logs for a minimum of seven years to support potential litigation holds.
Undergo an annual SOC 2 Type II audit covering security and availability controls.
Provide a mechanism for data subjects to request erasure of their personal data at any time.
The GDPR grants data subjects the right to erasure (commonly called the right to be forgotten) in Article 17. Any system processing personal data of EU residents must therefore include a capability to receive, authenticate, and execute erasure requests. While strong encryption, SOC 2 audits, and lengthy log retention may be advisable or required by other standards or contracts, they are not expressly mandated by the GDPR itself. Only the provision for data subjects to demand deletion of their personal data is a direct regulatory requirement under GDPR, making it the necessary feature to record in the compliance backlog.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the 'right to erasure' under GDPR?
Open an interactive chat with Bash
Why is encryption not explicitly required under GDPR?
Open an interactive chat with Bash
What is the difference between GDPR compliance and industry standards like SOC 2?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .