1/20
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
data governance
the process of managing information over its life cycle from creation to destruction
security operations center(SOC)
a location where security professionals monitor and protect critical information assets in an organization
SOCs usually exist for larger corporations, government agencies, and health care organizations
security control categories
AC - access control
AA - accountability
IR - incident response
RM - risk management
data classifications
unclassified - no restrictions on viewing, presents no risk to the organization for publicly disclosed information
classified - viewing is restricted to authorized persons within the organization or third parties under an NDA
confidential - highly sensitive data that is for viewing only by approved persons within the organization (and possibly by trusted third parties under NDA)
secret - information that is valuable and must be protected by severely restricting its viewing
top secret - information that would cause grave danger if inadvertently disclosed
declassification
the downgrading of a classification label over time as information no longer requires additional security protections it provides
general data protection regulation(GDPR)
personal data cannot be collected, processed, or retained without the individual’s informed consent
provides the right for a user to withdraw consent, to inspect, amend, or erase data held about them
sarbanes-oxley act(SOX)
sets forth the requirements for the storage and retention of documents relating to an organization’s financial and business operations, including the type of documents to be stored and their retention periods
gramm-leach-bliley act(GLBA)
sets forth the requirements that help protect the privacy of an individual’s financial information that is held by financial institutions
federal information security management act(FISMA)
sets forth the requirements for federal organizations to adopt information assurance controls
health insurance portability and accountability act(HIPAA)
sets forth the requirements that help protect the privacy of an individual’s health information that is held by healthcare providers, hospitals, and insurance companies
purpose limitation
the principle that personal information can be collected and processed only for a stated purpose to which the subject has consented
data minimization
the principle that only necessary and sufficient personal information can be collected and processed for the stated purpose
data sovereignty
the principle that countries and states may impose individual requirements on data collected or stored within their jurisdiction
data owner
a senior executive role with ultimate responsibility for maintaining the confidentiality, integrity, and availability of the information asset
the data owner is responsible for labeling the asset and ensuring that it is protected with appropriate controls
data steward
a role focused on the quality of the data and associated metadata
data custodian
a role responsible for handling the management of the system on which the data assets are stored
privacy officer
a role responsible for the oversight of any PII/SPI/PHI assets managed by the company
service level agreement(SLA)
a contractual agreement setting out the detailed terms under which a service is provided
interconnection security agreement(ISA)
an agreement used by federal agencies to set out a security risk awareness process and commit the agency and supplier to implementing security controls
non disclosure agreement(NDA)
a contract that sets forth the legal basis for protecting information assets between two parties
data sharing and use agreement
an agreement that sets forth the terms under which personal data can be shared or used