CISSP Domain 2: Managing Data Lifecycle Flashcards

1
Q

What are data roles?

A

different responsibilities and roles associated with the management and protection of data assets within an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the different data roles?

A
  • Data Owner
  • Data Controller
  • Data Custodian
  • Data Processor
  • Data Users/Subjects
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe data owner and their key responsibilities

A
  • typically a senior-level individual within an organization who has the ultimate responsibility for a specific set of data assets
  • key responsibilities of a data owner include:
    • determining the classification and sensitivity of data
    • establishing and communicating data handling and usage policies
    • authorizing access rights and permissions for data
    • ensuring compliance with relevant laws, regulations, and contractual obligations
    • reviewing and approving requests for data access or changes to access permissions
    • collaborating with other stakeholders to establish data governance strategies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Describe Data Controller and their key responsibilities

A
  • entity or organization that determines the purposes, conditions, and means of processing personal data
  • key responsibilities of a data controller include:
    • identifying the legal basis and purpose for data processing
    • implementing appropriate data protection policies and procedures
    • ensuring data processing activities align with data subject rights and consent requirements
    • maintaining records of data processing activities and associated documentation
    • assessing and managing data privacy risks and impact assessments
    • coordinating with data processors and other stakeholders to ensure compliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Desctibe Data Custodian and their key responsibilities

A
  • responsible for the technical implementation, management, and protection of data assets
  • handle the day-to-day operations of data storage, access, and maintenance
  • key responsibilities of a data custodian include:
    • implementing and managing technical controls for data protection, such as access controls, encryption, backups, and data retention policies
    • ensuring data integrity, availability, and confidentiality
    • monitoring and auditing data access and usage
    • implementing and maintaining data backup and recovery mechanisms
    • managing user accounts and access privileges to data systems
    • collaborating with data owners and users to enforce data handling policies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the stages of data lifecycle?
Name from the beginning

A
  1. Data Collection
  2. Data Analysis
  3. Data Usage
  4. Data Retention
  5. Data Destruction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Admin asked to scrub data to remove data that is no longer needed by an organization is what phase of the data lifecycle?

A

data maintenance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the entity assigned specific responsibility for a data asset in order to ensure its protection for use by the organization?

A

data owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly