CCSP Domain 2

0.0(0)
Studied by 1 person
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/68

flashcard set

Earn XP

Description and Tags

Last updated 9:30 PM on 2/17/23
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

69 Terms

1
New cards
Agent of the government
A private citizen becomes an agent of the government when they perform an act that the government would need a warrant for, such as a search and seizure. Under those circumstances, the citizen must follow the same rules as the government.
2
New cards
Baselines
Minimum requirements, especially regarding security as a minimum level.
3
New cards
Cloud Controls Matrix (CCM)
Lists and categorizes the domains and controls, along with which elements and components are relevant per the controls. This framework enables cooperation between cloud consumers and cloud providers on demonstrating adequate risk management.
4
New cards
Conflict of law
The field of law that resolves the jurisdiction of states or nations with laws that are not in agreement with other states or nations, either domestically or internationally.
5
New cards
Criminal law
The body of law that relates to crime. It proscribes conduct perceived as threatening, harmful, or otherwise endangering to the property, health, safety, and moral welfare of people. Most criminal law is established by statute, which is to say that the laws are enacted by a legislature.
6
New cards
Cross-border transfers
Multiple laws and regulations restrict or do not allow for information to be transferred across borders or to locations where the level of privacy or data protection is deemed to be weaker than their current requirements.
7
New cards
CSA Security, Trust and Assurance Registry (STAR)
The provider will have assessments and certifications that provide differing levels of assurance about the cloud controls they maintain. For instance, some providers have only completed a self-assessment, while others have completed a third-party certification based upon Information Security Management System ISO 27001. Still other organizations have completed a third-party attestation of their cloud controls based upon Service Organization's System in a SOC 2 Report.
8
New cards
Data sovereignty
Implied or explicit right to decide what treatment, care, or disposition (embargo or movement) a nation or state can determine on data by means of its laws.
9
New cards
Doctrine of plain view
In some U.S. states, a law enforcement officer may seize evidence without a search warrant if they can see it without making entry to where the evidence resides. This applies in digital forensic searches because it is necessary to perform various kinds of searches on digital evidence that may reveal evidence of a crime not noted in the warrant.
10
New cards
Due care
"Due care" is a standard of behavior grounded in the concept of "reasonableness." Did the actor exhibit a standard of behavior that is deemed by the law to be "reasonable," i.e., would other individuals in the actor's position act in a similar manner exhibiting an expected standard of due care?
11
New cards
Due diligence
"Due diligence" is not a standard, but rather a mode of conduct. Did the actor do what is appropriate, reasonable, and expected in engaging in a certain activity?
12
New cards
European Economic Area (EEA)
The EEA includes EU countries and also Iceland, Liechtenstein, and Norway. It allows them to be part of the EU's single market.Switzerland is neither an EU nor EEA member, but is part of the single market—this means Swiss nationals have the same rights to live and work in the UK as other EEA nationals.
13
New cards
European Union (EU)
An economic and political union of 28 countries. It operates an internal (or single) market that allows free movement of goods, capital, services and people between member states. As of March 2019 these countries include: Austria, Belgium, Bulgaria, Croatia, Republic of Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and the UK.
14
New cards
E-discovery
Electronic discovery (also called e-discovery) refers to any process in which electronic data is sought, located, secured, and searched with the intent of using it as evidence in a civil or criminal legal case.
15
New cards
EU Data Protection Directive 95/46 EC
Directive 95/46 EC focuses on the protection of individuals regarding the processing of personal data and on the free movement of such data.
16
New cards
EU General Data Protection Regulation 2016
Introduces many significant changes for data processors and controllers. The following may be considered some of the more significant changes: the concept of consent, transfers abroad, the right to be forgotten, establishment of the role of the "data protection officer," access requests, home state regulation, and increased sanctions.
17
New cards
Extradition
Many countries support a formal process whereby one country transfers a suspected or convicted criminal to another country.
18
New cards
Generally Accepted Privacy Principles (GAPP)
The AICPA describes 74 privacy principles in detail. These serve as a framework for organizations to use to manage privacy risk.
19
New cards
Gramm-Leach-Bliley Act (GLBA)
Also known as the Financial Modernization Act of 1999, GLBA is a federal law enacted in the United States to control the ways that financial institutions deal with the private information of individuals.
20
New cards
Guidelines
Statements that aren't designed for enforcement, but principles that can assist in accomplishing objectives.
21
New cards
Harmonization of law
Specifically, in relation to the European Union, harmonization of law (or simply "harmonization") is the process of creating common standards across the internal market.
22
New cards
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Adopts national standards in the United States for electronic health care transactions and national identifiers for providers, health plans, and employers. Protected health information can be stored via cloud computing under HIPAA.
23
New cards
International law
The term given to the rules that govern relations between countries.
24
New cards
ISO/IEC 27017:2015
This standard provides guidance on the information security aspects of cloud computing, recommending and assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC 27002:2013 and other ISO27k standards. The "code of practice" provides additional information security controls implementation advice beyond that provided in ISO/IEC 27002:2013, in the cloud computing context.
25
New cards
ISO/IEC 27018:2019
The first international "code of practice" that focuses on protection of personal data in the cloud. It is based on ISO/IEC information security standard 27002:2013 and provides implementation guidance on ISO/IEC 27002:2013 controls applicable to public cloud personally identifiable information (PII).
26
New cards
ISO/IEC 27050
ISO/IEC 27050 consists of six major components across the discovery phase of a law suit, with an emphasis on the discovery of electronically stored information (ESI).
27
New cards
ISO/IEC 31000:2018
A guidance standard not intended for certification purposes, implementing it does not address specific or legal requirements related to risk assessments, risk reviews, and overall risk management.
28
New cards
Jurisdiction
The practical authority granted to a legal body to administer justice within a defined area of responsibility.
29
New cards
Legal hold
Once a party reasonably anticipates litigation, it must suspend its routine document retention/destruction policy and put in place a legal hold to ensure the preservation of relevant documents.
30
New cards
NIST SP 800-37r2
This publication details the NIST Risk Management Framework, a process for managing security and privacy risk. Integrates the Risk Management Framework (RMF) into the system development lifecycle (SDLC) Provides processes (tasks) for each of the six steps in the RMF at the system level.
31
New cards
NIST SP 800-53r4
A standard to ensure that appropriate security requirements and security controls are applied to all U.S. federal government information and information management systems.
32
New cards
Policies
The Privacy Act 1988 (Privacy Act) is an Australian law that regulates the handling of personal information about individuals. This includes the collection, use, storage, and disclosure of personal information, and access to and correction of that information.
33
New cards
Policy
General high-level statement that prescribes actions and consequences for organizational members.
34
New cards
Procedure
The methods and instructions on how to maintain or accomplish the directives of the policy.
35
New cards
Sarbanes-Oxley Act (SOX)
U.S. legislation enacted to protect shareholders and the general public from accounting errors and fraudulent practices in the enterprise.
36
New cards
Service Organization Controls 1 (SOC 1)
Reports on controls at a service organization relevant to user entities' internal control over financial reporting. Used to provide information to the auditor in order to enable risk assessment.
37
New cards
Service Organization Controls 2 (SOC 2)
Reports on controls at a service organization relevant to security, availability, processing integrity, confidentiality, and privacy. Used to provide management and specified entities with information.
38
New cards
Service Organization Controls 3 (SOC 3)
Reports on controls at a service organization relevant to security, availability, processing integrity, confidentiality, and privacy. Used to provide information for general use by any interested party.
39
New cards
Standards
Implementable selections of tools, technology, hardware, and software.
40
New cards
Subpoena
The subpoena is deemed issued by an officer of the court and must be obeyed in much the same manner as a warrant.
41
New cards
Tort law
A body of rights, obligations, and remedies that sets out reliefs for persons suffering harm because of the wrongful acts of others.
42
New cards
Trust Services Principles and Criteria (TSP)
An auditing system whereby various criterion areas are evaluated along with controls within an organization.
43
New cards
Warrant
Authorization issued by a magistrate or other official allowing a constable or other officer to search or seize property, arrest a person, or perform some other specified act.
44
New cards
At what 2 stages of the data life cycle is data EXPOSED?
Use and Share phases
45
New cards
3 parts to data encryption

1. the data itself
2. encryption engine that holds all activities
3. encryption keys used in the actual encryption
46
New cards
data in transit
active transmission of data across the network
47
New cards
central challenge in encryption of data
security of encryption keys that handle the encryption and decryption process
48
New cards
IRM
information rights management
49
New cards
key storage implementation
simplest - internal storage on the vm w/ encryption service

external storage - similar to encryption

have an external AND independent service/system host the key storage.
50
New cards
tokenization
utilizing a random and opaque ā€œtokenā€ value in data to replace what otherwise would be a sensitive or protected object.
51
New cards
DLP
data loss prevention - a set of controls and practices put in place to ensure that data is only accessible to authorized users.
52
New cards
What are the 3 components of DLP?

1. discovery and classification
2. monitoring
3. enforcement
53
New cards
examples of DAR
servers, desktops, workstations, mobile devices
54
New cards
DAR vs. DIT vs. DIU

(where would DLP be deployed?)
DAR - DLP is deployed on the systems holding the data

DIT - DLP is deployed on the network perimeter through protocols like HTTP/HTTPS/SMTP.

DIU - deployed on the users’ workstation or devices in order to monitor the data access and use from the endpoint.
55
New cards
Data De-identification
uses masking, obfuscation, and anonymization to replace, hide or remove sensitive data from data sets.
56
New cards
static masking
a separate and distinct copy of the data set is created with masking in place. typically done in nonproduction environments.
57
New cards
dynamic masking
the masking process is implemented between the application and data layers of the application.
58
New cards
data anonymization
data is manipulated to prevent the identification of an individual through various data objects. (used other concepts like masking)
59
New cards
direct identifiers vs. indirect identifiers
direct- actual personal or private data

indirect- the attributes of the data (demographics or location)
60
New cards
steps to apply tech within the environment

1. understand the data that is to be protected.
2. understand the nature and details of the hosting environment
3. determine the data ownership and classification reqs.
4. monitoring and auditing need to be planned and tested b4 rollout.
61
New cards
examples of unstructured data
documents/text files, emails, pictures, videos, office documents, scientific data, sensory data or imagery intelligence, weather data
62
New cards
Data Classification
process of analyzing data for certain attributes and then using the to determine the appropriate policies and controls to apply.
63
New cards
metadata
contains information about the data (type, stored and organized)
64
New cards
3 types of sensitive data

1. Protected Health Information(PHI)
2. Personally Identifiable Information(PII)
3. Cardholder Data(CD)
65
New cards
Who puts controls on how PHI data is to be handeled?
HIPAA
66
New cards
What is CCM?
Cloud security alliance’s cloud controls matrix
67
New cards
What is DRM
Data Rights Management-extension of normal data protection to ACL and placed on data sets that require additional permissions.
68
New cards
what is IRM
information rights management
69
New cards
tools for IRM
auditing, expiration, policy control, protection, support for applications and formats