1 / 34100%
Name
Strayer University
Assignment 4: Designing GDPR Technical Safeguards for a Data-Driven Marketing Agency
CIS 349 – Information Technology Audit and Control
Assignment 4: Designing GDPR Technical Safeguards for a Data-Driven
Marketing Agency
Imagine you are an Information Security consultant for a data-driven marketing agency that
processes personal data of European Union (EU) citizens. The agency must comply with the
General Data Protection Regulation (GDPR). Write a three to five-page paper in which you:
1. Analyze proper physical access control safeguards for the agency's data servers and
provide recommendations for securing personal data.
2. Recommend the proper audit controls to be employed to monitor data processing
activities and access to personal data.
3. Suggest three logical access control methods to restrict unauthorized access to personal
data, and explain why you suggested each method.
4. Analyze how personal data is transferred between the agency and its clients, and
identify techniques that may be used to provide data transmission security safeguards.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all
sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Describe the role of information systems security (ISS) compliance and its relationship to
U.S. compliance laws.
Use technology and information resources to research issues in security strategy and
policy formation.
Write clearly and concisely about topics related to information technology audit and
control using proper writing mechanics and technical style conventions.
Clickhereto view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 50 Assignment 4: Designing GDPR Technical Safeguards for a Data-Driven Marketing Agency
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplar
90-100%
1. Analyze proper
physical access
control
safeguards and
provide sound
recommendation
s to be employed
in the registrar's
office.
Weight: 21%
Did not submit or
incompletely analyzed
proper physical access
control safeguards and did
not submit or incompletely
provided sound
recommendations to be
employed in the registrar's
office.
Insufficiently
analyzed proper
physical access
control safeguards
and insufficiently
provided sound
recommendations to
be employed in the
registrar's office.
Partially analyzed
proper physical
access control
safeguards and
partiallyprovided
sound
recommendation
s to be employed
in the registrar's
office.
Satisfactorily
analyzed proper
physical access
control safeguards
and satisfactorily
provided sound
recommendations to
be employed in the
registrar's office.
Thoroughly
analyzed prope
physical acces
control safegua
and thoroughly
provided sound
recommendati
to be employed
the registrar's o
2. Recommend
the proper audit
Students also viewed