13. Mission, data, system owners, and data custodians Flashcards

1
Q

Mission, data, system owners, and data custodians

Mission/Business Owners

A

Senior executives

  • Make the policies that govern data security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Mission, data, system owners, and data custodians

Data/Information Owners

A

Management Level

  • Assign sensitivity labels and backup frequency
  • Approve access but do not grant access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Mission, data, system owners, and data custodians

Data Custodians

A

Technical Hands-on Employees

  • Hands on employees who do backups, restores, patches and system config
  • Do backups and restores at the direction of the data owner
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Mission, data, system owners, and data custodians

System Owner

A

Management Level

  • Owner of the systems that house the data
  • Responsible for security profile of the system
  • Data center manager or infrastructure manager as example
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Mission, data, system owners, and data custodians

Data Controllers

A

Create and manage sensitive data

  • For example, HR or Payroll
  • Security could audit the processes of teams to ensure they are handling data correctly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Mission, data, system owners, and data custodians

Data Processors

A

Manage data for controllers

  • for example, outsourced payroll
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Mission, data, system owners, and data custodians

Security Administrators

A
  1. Firewalls
  2. IPS / IDS
  3. Security patches
  4. Account creation
  5. Assign access to data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Mission, data, system owners, and data custodians

Supervisors

A
  1. Responsible for user behaviour and assets created by users
  2. Responsible for user awareness
  3. Needs to inform Sec admin of changes to employment of users and permissions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Mission, data, system owners, and data custodians

Users

A

Users of the data

  • Must be trained and made aware
  • Need to understand what is acceptable and not acceptable
  • Understand the consequences of not following policies, procedures, and standards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Mission, data, system owners, and data custodians

Auditors

A

Reviewing and confirming security policies are implemented

  • validate they provide the protection that they should
  • Can be internal or external
How well did you know this?
1
Not at all
2
3
4
5
Perfectly