Week 7 - AIS Control Frameworks Flashcards
(14 cards)
What are information security controls
Measures and mechanisms put in place to protect the confidentiality, integrity and availability of information assets
What are the 3 primary categories of information security controls
- Preventative controls
- Detective controls
- Response controls
What do preventative controls entail
- Administrative controls
- Process controls
- IT solution
What do detective controls entail
- Physical security controls
- Intrusion detection controls
What do response controls entail
- Compyter security incident response teams (CSIRT)
- Chief information security officer (CISO)
Name 3 policies of personal information protection
- General Data Protection Regulation (GDPR)
- Protection of Personal Information Act
- Cybercrimes Act
What is the primary objective of GDPR
Harmonize data protection regulations across the EU member states, as well as to provide greater protection control over personal data for EU citizens
What are some of the rights the GDPR ensures
- The right to be informed
- The right of access
- The right to object
What are the principles of the GDPR
- Expanded scope
- Consent
- Data subject rights
- Accountability and governance
- Data breach notification
- Data protection impact assessments (DPIA)
- Cross-border data transfers
- Penalties
What is the aim of POPI Act
Regulate the processing of personal information by public and private bodies in order to protect the privacy rights of individuals
What are some of the rights the POPI Act ensures
- The right to access personal information
- The right to request correction for personal information
- The right to request deletion of personal information
Wahat are the key principles of POPIA
- Definition of personal information
- Principles of processing
- Consent
- Data subject rights
- Data protection officer
- Data breach notification
- Cross-border data transfers
- Enforcement and penalties
What is the purpose of the Cybercrimes Act
It aims to address evolving challenges posed by cyber threats and to strengthen the legal framework for combating cybercrimes in SA
What ar the key principles of Cybercrimes Act
- Definition
- Prohibited activities
- Penalties
- Investigation and prosecution
- Protection of critical infrastructure
- Reporting obligations
- International cooperation