Week 7 - AIS Control Frameworks Flashcards

(14 cards)

1
Q

What are information security controls

A

Measures and mechanisms put in place to protect the confidentiality, integrity and availability of information assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 3 primary categories of information security controls

A
  1. Preventative controls
  2. Detective controls
  3. Response controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do preventative controls entail

A
  • Administrative controls
  • Process controls
  • IT solution
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What do detective controls entail

A
  • Physical security controls
  • Intrusion detection controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What do response controls entail

A
  • Compyter security incident response teams (CSIRT)
  • Chief information security officer (CISO)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name 3 policies of personal information protection

A
  1. General Data Protection Regulation (GDPR)
  2. Protection of Personal Information Act
  3. Cybercrimes Act
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the primary objective of GDPR

A

Harmonize data protection regulations across the EU member states, as well as to provide greater protection control over personal data for EU citizens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some of the rights the GDPR ensures

A
  • The right to be informed
  • The right of access
  • The right to object
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the principles of the GDPR

A
  • Expanded scope
  • Consent
  • Data subject rights
  • Accountability and governance
  • Data breach notification
  • Data protection impact assessments (DPIA)
  • Cross-border data transfers
  • Penalties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the aim of POPI Act

A

Regulate the processing of personal information by public and private bodies in order to protect the privacy rights of individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are some of the rights the POPI Act ensures

A
  • The right to access personal information
  • The right to request correction for personal information
  • The right to request deletion of personal information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Wahat are the key principles of POPIA

A
  • Definition of personal information
  • Principles of processing
  • Consent
  • Data subject rights
  • Data protection officer
  • Data breach notification
  • Cross-border data transfers
  • Enforcement and penalties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of the Cybercrimes Act

A

It aims to address evolving challenges posed by cyber threats and to strengthen the legal framework for combating cybercrimes in SA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What ar the key principles of Cybercrimes Act

A
  • Definition
  • Prohibited activities
  • Penalties
  • Investigation and prosecution
  • Protection of critical infrastructure
  • Reporting obligations
  • International cooperation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly