Data Protection Flashcards
(58 cards)
Information is subject to the laws & governance structures within their nation where it is collected. Refers to the concept that digital information is subject to the laws of the country in which it is located.
Data Sovereignty
Strategy for ensuring sensitive or critical information does not leave an organization. Set up to monitor the data of a system while it’s in use, in transit, or at rest in order to detect any attempts to steal the data.
Data Loss Prevention (DLP)
Category based on the organization’s value & the sensitivity of the information if it were to be disclosed.
Data Classification
Any information that can result in a loss of security or a loss of advantage to a company if accessed by an unauthorized person.
Sensitive Data
Has no impact on the company if released & is often posted in an open -source environment.
Public Data
Has minimal impact if released (organization’s financial data).
Sensitive Data
Contains data that should only be used within the organization.
Private Data
Contains items such as trade secrets, intellectual property data, & source code that affect the business if disclosed.
Confidential Data
Contains valuable information.
Critical
Data that can be released to the public or under the Freedom of Information Act.
Unclassified
Data that would not hurt national security if released but could impact those whose data was being used.
Sensitive but Unclassified.
Data that could seriously affect the government if unauthorized disclosures happen.
Confidential (Government)
Data that could seriously damage national security if it is disclosed.
Secret
Data that would damage national security if it is disclosed.
Top Secret
Process of identifying the person responsible for the confidentiality, integrity, availability, & privacy of the information assets.
Data Ownership
Senior executive role that has the responsibility for maintaining the confidentiality, integrity, and availability of the information assets.
Data Owner
Entity that holds responsibility for deciding the purposes & methods of data storage, collection, and usage, and for guaranteeing the legality of processes.
Data Controller
Group or individual hired by the data Controller to help with tasks like collecting, storing, or analyzing data.
Data Processor
Focused on the quality of the data & the associated metadata.
Data Steward
Responsible for handling the management of the system on which the data assets are stored.
Data Custodian (System Administrator)
Role that is responsible for the oversight of any kind of privacy-related data, like PII, SPI, or PHI.
Privacy Officer
Should be a business entity responsible for creating this information; know more about the data based on the content of the company, with each owner being assigned to their own department.
Who should be the data owner?
These people should never be the data owner.
I.T. People
Refers to any data stored in databases, file systems, or other storage systems.
Data at Rest