non-technical data and privacy controls

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/20

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:56 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

21 Terms

1
New cards

data governance

the process of managing information over its life cycle from creation to destruction

2
New cards

security operations center(SOC)

a location where security professionals monitor and protect critical information assets in an organization

  • SOCs usually exist for larger corporations, government agencies, and health care organizations

3
New cards

security control categories

AC - access control

AA - accountability

IR - incident response

RM - risk management

4
New cards

data classifications

unclassified - no restrictions on viewing, presents no risk to the organization for publicly disclosed information

classified - viewing is restricted to authorized persons within the organization or third parties under an NDA

confidential - highly sensitive data that is for viewing only by approved persons within the organization (and possibly by trusted third parties under NDA)

secret - information that is valuable and must be protected by severely restricting its viewing

top secret - information that would cause grave danger if inadvertently disclosed

5
New cards

declassification

the downgrading of a classification label over time as information no longer requires additional security protections it provides

6
New cards

general data protection regulation(GDPR)

personal data cannot be collected, processed, or retained without the individual’s informed consent

  • provides the right for a user to withdraw consent, to inspect, amend, or erase data held about them

7
New cards

sarbanes-oxley act(SOX)

sets forth the requirements for the storage and retention of documents relating to an organization’s financial and business operations, including the type of documents to be stored and their retention periods

8
New cards

gramm-leach-bliley act(GLBA)

sets forth the requirements that help protect the privacy of an individual’s financial information that is held by financial institutions

9
New cards

federal information security management act(FISMA)

sets forth the requirements for federal organizations to adopt information assurance controls

10
New cards

health insurance portability and accountability act(HIPAA)

sets forth the requirements that help protect the privacy of an individual’s health information that is held by healthcare providers, hospitals, and insurance companies

11
New cards

purpose limitation

the principle that personal information can be collected and processed only for a stated purpose to which the subject has consented

12
New cards

data minimization

the principle that only necessary and sufficient personal information can be collected and processed for the stated purpose

13
New cards

data sovereignty

the principle that countries and states may impose individual requirements on data collected or stored within their jurisdiction

14
New cards

data owner

a senior executive role with ultimate responsibility for maintaining the confidentiality, integrity, and availability of the information asset

  • the data owner is responsible for labeling the asset and ensuring that it is protected with appropriate controls

15
New cards

data steward

a role focused on the quality of the data and associated metadata

16
New cards

data custodian

a role responsible for handling the management of the system on which the data assets are stored

17
New cards

privacy officer

a role responsible for the oversight of any PII/SPI/PHI assets managed by the company

18
New cards

service level agreement(SLA)

a contractual agreement setting out the detailed terms under which a service is provided

19
New cards

interconnection security agreement(ISA)

an agreement used by federal agencies to set out a security risk awareness process and commit the agency and supplier to implementing security controls

20
New cards

non disclosure agreement(NDA)

a contract that sets forth the legal basis for protecting information assets between two parties

21
New cards

data sharing and use agreement

an agreement that sets forth the terms under which personal data can be shared or used