金融機関のコンプライアンス担当者であるジェームズは、規制要件を満たしていることを確認するため、会社のデータ保護ポリシーを精査する任務を負っている。同社は、ローン、投資アドバイス、保険など、幅広い金融商品とサービスを提供している。ジェームズは精査の中で、同社が顧客にデータ共有に関する明確な情報を提供し、機密データを保護するための措置を実施していることに気づいた。彼は、金融機関に対し情報共有の実態を説明し、機密データを保護することを義務付ける1999年制定の法律を同社が遵守していると確信している。
ジェームズは、以下のどの法律の遵守を確保しようとしているのか?
正解:D
Option D. GLBA is the correct answer. The Gramm-Leach-Bliley Act (GLBA) is the U.S. law enacted in
1999 that requires financial institutions to explain their information-sharing practices and protect sensitive customer data through safeguards. That description matches the scenario exactly. Within CHFI v11, legal awareness is a core competency: the blueprint includes legal issues, privacy issues and legal compliance , other laws that may influence computer forensics , and rules tied to the admissibility and handling of digital evidence.
The other options do not fit the facts. GDPR is a European data protection regulation, not a 1999 U.S.
financial law. HIPAA governs protected health information in the healthcare sector. PCI DSS is an industry security standard for payment card data, not a law enacted in 1999 requiring disclosure of information-sharing practices. Because the company is a financial institution and the question highlights both privacy notice and safeguarding customer information , GLBA is the only answer that fully matches the scenario.
From a CHFI perspective, recognizing applicable legal frameworks is important because investigators and compliance personnel must understand which laws govern digital evidence, privacy obligations, and organizational handling of sensitive information.