Geographic Restrictions Explained: Geofencing and Data Sovereignty for Security+
Geographic restrictions — also called geofencing , geolocation-based access control , or simply geo-blocking — limit access to systems and data based on where the request appears to originate. They show up on the Security+ exam in two distinct contexts, and conflating them is the common mistake. Geographic restrictions are used both as an access control, deciding who may connect, and as a compliance control, deciding where data may physically live. The Two Uses As an access control. If your organization operates only in North America, there is no legitimate reason for an authentication attempt from another continent. Blocking or challenging those requests removes a large volume of opportunistic attack traffic immediately, and it is one of the cheapest risk reductions available. As a compliance control — data sovereignty. A great many regulations require that certain data stay within a jurisdiction. GDPR constrains transfers of EU personal data outside the EEA. Various nation...