A cloud administrator disables multi-factor authentication on systems holding citizen personal data to 'reduce friction.' How should this change be viewed under GDPR security expectations?
Select an answer to reveal the explanation.
Short Explanation
Turning off MFA to make login 'easier' is like unlocking the city vault because the key was annoying. Strong access control is part of the security package GDPR expects. Friction for attackers is a feature, not a bug, when citizen data is inside.
Full Explanation
Article 32 requires measures appropriate to the risk, commonly including robust authentication and access control for systems processing personal data. Removing MFA solely for convenience typically weakens those TOMs and should be treated as a security regression requiring risk reassessment, compensating controls, or restoration—not a compliance improvement.