Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Enterprise Resource Management

A company runs a hybrid two-tier ERP model: a large headquarters ERP and a lighter cloud ERP at its subsidiaries, with data flowing between them through APIs and middleware. Customer personal data of Indian residents is stored in the cloud instance. Which approach best reflects sound practice?

Sound practice is to use authenticated, encrypted API links, role-based access and activity logging, and to treat the subsidiary cloud instance as covered by data protection and security obligations. Being in the same group, or being a lighter system, does not remove the duty to protect personal data.

  1. AAllow middleware to pass data without authentication since both systems belong to the same group
  2. BUse authenticated, encrypted API connections, role-based access and logging, and treat the subsidiary's cloud instance as within the scope of data protection and IT security obligationsCorrect
  3. CDisable audit logs in the cloud instance to improve performance
  4. DExempt the subsidiary instance from security controls because it is a lighter system

Explanation

Integration points are common attack surfaces, so authentication, encryption in transit, role-based access and audit logs are expected. Data protection and reasonable security practice obligations apply wherever personal data is held, including subsidiary and cloud systems. Intra-group trust, disabled logs or lighter size do not remove these duties.

Did you get it right without looking?

One question tells you little. A timed set on Enterprise Resource Management shows your real accuracy, how long you take and where you lose marks.

More Enterprise Resource Management questions