Domain 2 - Asset Security Flashcards
what are the stages to data lifecycle
- create/update
- store/classification
- use
- share
- archive
- destroy - data cant stay around longer than necessary. it creates risk and liability. It can be stolen, it can be called as evidence for legal actions
What are some data security controls
- marketing, labeling, handling, classifications - classifications is the most important
- data handling - shipping, chain of custody. dont open boxes
- data destruction - erasing, clearing (overwriting w/ unclassified data)
record retention - if the retention policy is 1 year, it should be destroyed when it ages out @ 1 year - tape backup security - secure offsite facility, tapes labeled, ensure all understand the classification of the data
what is a security control baseling
- provides a listing of controls that an organization can apply as a baseline
- a group of controls that can be applied as a base standard or starting point that we work from
when it comes to data protection, what can you use to guarantee confidentiality
encryption
should asset classification match data classification
yes
what is (PII) personally identifiable information
- any information that can identify and individual
- (name (non common), SSN, birthdate/place, biometric records, education, medical history, financial transactions, mothers maiden name, criminal or employment history, etc.)
what is (PHI) protected health information
health related information that can be related to a specific person (covered by HIPAA)
define Data owner/controller
- usually a member of senior management or the board
- accountable for the protection of data
- define level of classification - responsible for security decisions for DATA
- holds legal rights and defines policies
- can delegate some duties
- can not delegate responsibility
define data custodian
- usually a member of IT
- does not decide what controls are needed
- implements controls from the data owner
- grants permissions, monitors, data archive, backup and restore checks, etc.
**** on behalf of the data owner
define data administrator
- responsible for granting appropriate access to personnel (often via RBAC) - roll based access control
define user
any person who accesses data via a computing system to accomplish work tasks
define business/mission owner
- senior executives make the policies that govern our data security
- can overlap or or be the same as the system owner
define system owner
- management level and owner of the systems that house the data
- often a data center manager or infrastructure manager
define security administrators
- responsible for firewalls, IPS, IDS, security patches, creates accounts
- grants access to data following the data owners direction
define supervisor
- responsible for user behavior and assets created by the users
- responsible for user awareness
- needs to inform the security administrator if there are any changes to user employment status, user access rights or any other pertinent changes to employees status
define asset owner
- owns assets or systems that process sensitive data and associated security plans
should each asset have an owner
yes, the owner is accountable for the protection of an asset
what do baselines define
minimum security requirements for each class
define classification
a system of classes ordered according to value
example: public, proprietary, confidential is one possibility of the the three classification an organization might use to define classes, with public being the least valuable and confidential being the most valuable
what is labeling of an asset
- noting the classification of an asset on an asset.
- the what, what the classification is
example: putting a label on a backup tape noting that its top secret
what is marking of an asset
- the how the asset should be protected based on its classification
- involves noting the handling instructions on the asset based on the classification
what is categorization
- the act of sorting assets into the defined classes
- its a process of putting assets into different classes
define data processor
- responsible for processing data on behalf of the owner
typical example: cloud service provider. they are storing and processing data on behalf of the owner
define data subject
- the individual to whom any personal data relates, its data about them