LO6 Flashcards
(82 cards)
What are the three key principles of data security?
Confidentiality, Integrity, Availability
These principles are protected under legislation such as the Data Protection Act (2018).
What does ‘confidentiality’ mean in the context of data security?
Information should only be accessed by individuals or groups with the authorisation to do so.
How can an organisation uphold confidentiality?
Using protection measures like usernames and passwords, tiered levels of access or permissions.
What does ‘integrity’ mean in the context of data security?
Information is maintained so that it is up-to-date, correct and fit for purpose.
How can an organisation preserve the integrity of its data?
Carrying out regular data maintenance, using record-locking in spreadsheets or databases.
What does ‘availability’ mean in the context of data security?
Information is available to the individuals or groups that need to use it and should only be available to those who are authorised.
How can an organisation keep its data available?
Ensuring staff have the correct privileges, storing data online (e.g. cloud storage).
Fill in the blank: Information should only be accessed by individuals or groups with _______.
authorisation
True or False: Data must be kept safe from unauthorized access.
True
Fill in the blank: Regular data maintenance helps ensure the information is _______.
up-to-date
What are two methods to limit access to sensitive data?
Using usernames and passwords, tiered levels of access or permissions.
What is a potential risk of making additional copies of information?
It could be lost or stolen.
What is the purpose of record-locking in data management?
To prevent multiple persons from editing data at the same time, ensuring correctness.
What is the security principle of confidentiality?
Data should only be viewed by individuals with the authorisation to do so.
What are the two main reasons why data may be viewed by unauthorized individuals?
- Espionage
- Poor information management
Define espionage in the context of data security.
The act of collecting data to use against an organisation.
What can result from poor information management regarding data access?
Data may be insecurely stored or too many people may have access to sensitive information.
What legal act is breached if personal data is accessed without authorization?
The Data Protection Act (2018)
What does accidental data loss refer to?
Information being irretrievably lost, including the original version.
List two reasons for accidental data loss.
- Equipment failure
- Human error
What is a consequence of accidental data loss?
It could delay dependent processes such as analysis and trend recognition.
What is intentional destruction of data?
Purposely damaging an organisation by deleting or denying access to data.
Give two examples of intentional destruction of data.
- Viruses that corrupt data
- Ransomware
What could happen if data destruction is ignored and unreported?
It could result in a huge loss of trust when revealed.