Lessons 25-29 Flashcards
(47 cards)
THIRD-PARTY RISK MANAGEMENT
Is a composite of activities used to research and source third parties, conduct due diligence investigations, negotiate contracts, manage relationships, evaluate performance, and make payments
THIRD-PARTY OVERSIGHT
The implementation of strategies to manage uncertainty, identify vulnerabilities, and ensure compliance and continuity.
RIGHT TO AUDIT
A “right to audit” contract provision (clause) grants the contract holder the right to conduct or oversee an audit of the service provider’s facilities and practices.
MOU
memorandum of understanding is a non-binding document that outlines the intentions and areas of cooperation between parties
MOA
memorandum of agreement is a legally enforceable document that establishes a contractual relationship between parties.
BPA
business partner agreement is a comprehensive legal document that outlines the terms and conditions of a relationship between two or more businesses or entities
SLA
a service-level agreement codifies service and support requirements and may include incentives and or penalties.
MSA
a master services agreement outlines general terms and conditions. It serves as a framework for future agreements or projects between the parties.
SOW
a statement of work that defines tasks, deliverables, timelines, and performance expectations for a particular project or engagement between a client and a service provider
WO
a work order is transactional and used for individual service requests, often within the context of ongoing business relationships.
Data minimization-
approach limits data collection to only what is required to fulfill a specific purpose
RIGHT TO BE FORGOTTEN
Pertains to an individual’s right to have their personal information removed or deleted from online platforms, search engine results, or other publicity accessible sources.
Data controller-
determines the purposes for which, and the means by which, personal data is processed
Data processor
processes personal data on behalf of the data controller
Data protection officer
ensures that an organization is in compliance with privacy regulations as defined in the GDPR: independence is required.
Data masking
a technique used to protect sensitive data by replacing it with fictional or de-identified data
Tokenization
a technique to secure and desensitize data by replacing the original data with an unrelated value of the same length and format
Anonymization
the process in which individually identifiable data is altered in such a way that it no longer can be related back to a given individual
Pseudo-anonymization-
a method to substitute identifiable data with a reversible consistent value.
PRIVACY IMPACT ASSESSMENT (PIA)
is a process used to evaluate how an organization’s projects, systems, or practices affect the privacy of individuals’ personal data. It helps identify and mitigate privacy risks, ensuring that data handling complies with privacy laws and regulations.
PRIVACY STATEMENT
Describes how an organization collects, uses, shares, and protects personal information collected from individuals
INFORMATION SECURITY ASSESSMENT
Is the process of determining how effectively the entity being evaluated meets specific security criteria
Examination
the process of interviewing, reviewing, inspecting, studying, and observing to facilitate understanding, comparing to standards or baselines, or to obtain evidence (audit)
Testing-
the process of exercising objects under specified conditions to compare actual and expected behavior (penetration testing)