Domain 2 Flashcards

1
Q

Data lifecycle

A

Create
Store
Use
Share
Archive
Destroy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Government Data Classification

A

Top Secret(class 3)
Secret(class 2)
Confidential(class 1)
Unclassified(class 0)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Non-gov’t( public) data classification

A

Confidential/Proprietary (class 3)
Private (class 2)
Sensitive (class 1)
Public (class 0)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data Security Controls

A

Marking, labeling, handling, classification
Data handling
Data destruction
Record retention
Tape backup security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Erasing

A

A data destruction method where a delete operation against a file, files, or media is performed. Data is typically recoverable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Clearing (overwriting)

A

A data destruction method that prepares media for reuse and ensuring data cannot be recovered using traditional recovery tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Purging

A

A data destruction method that is more intense form of clearing that prepares media for reuse in less secure environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Degaussing

A

A data destruction method that creates a strong magnetic field that erases data on some media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Destruction

A

A data destruction method that is the final stage in the lifecycle of media and is the most secure method of sanitizing media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security Control Baseline

A

Provides a listing of controls that an organization can apply as a baseline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data protection

A

Confidentiality is often protected through encryption ( at rest and in transport)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Asset classification

A

Asset classification should match the data classification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Sensitive Data

A

Is any information that isn’t public or unclassified. Example: Personally identifiable information (PII), Protected Health Information(PHI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Data Owner

A

Usually a member of senior management. Can delegate some day to day duties. Cannot delegate total responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Data Custodian

A

Usually someone in the IT department. Does not decide what controls are needed but does implement controls for data owner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Data Administrators

A

Responsible for granting appropriate access to personal ( often via RBAC)

17
Q

User

A

Any person who accesses data via a computing system to accomplish work tasks

18
Q

Business/Mission Owners

A

Can overlap with the responsibilities of the system owner or be same role

19
Q

Asset Owners

A

Owns asset or system that processes sensitive data and associated security plans

20
Q

Data Processor

A

A GDPR term which is a natural or legal person, public authority, agency, or other body which processes personal data solely on behalf of the data controller

21
Q

Data Controller

A

A GDPR term which is a person or entity that controls processing of the data

22
Q

Data Transfer

A

A GDPR term which the GDPR restricts data transfers to countries outside the EU

23
Q

Anonymization

A

The process of removing all relevant data so that it is impossible to identify original subject or person. If done effectively the GDPR is no longer relevant for the anonymized data. Use this if the data is not needed.

24
Q

Pseudonymization

A

The process of using pseudonyms (aliases) to represent the data. Can result in less stringent requirements than would otherwise apply under the GDPR. Use if you need data and want to reduce exposure