19-C Flashcards
What is the consequence of breaching confidential data?
Almost impossible to recover and re-secure
Breaches can lead to significant reputational damage and legal implications.
What is regulated data?
Information that must be collected, processed, and stored in compliance with federal and/or state legislation
Define a data breach.
When confidential or regulated data is read, copied, modified, or deleted without authorization
What is personally identifiable information (PII)?
Data that can be used to identify, contact, or locate an individual
Give examples of PII.
- Name
- Date of birth
- Email address
- Street address
- Biometric data
What are examples of personal government-issued information?
- Social security number (SSN)
- Passport
- Driving license
- Birth/marriage certificates
What does healthcare data include?
Medical and insurance records plus associated hospital and laboratory test results
What is the PCI DSS?
Payment Card Industry Data Security Standard governing processing of credit card transactions
What is a key aspect of data handling best practices?
Training employees to identify PII and handle sensitive data appropriately
What are data retention requirements?
Regulations that may set maximum or minimum periods for the retention of data
What constitutes prohibited content?
Any information not applicable to work, including obscene or illegally copied content
What is an end-user license agreement (EULA)?
A license governing the use of software, often restricting installation to one computer or user
What is a personal license in software terms?
Allows the product to be used by a single person at a time, potentially on multiple devices
What is the role of a Computer Security Incident Response Team (CSIRT)?
To provide a single point-of-contact for reporting security incidents
True or False: Involving law enforcement in an incident investigation is always under the organization’s control.
False
What is digital forensics?
The science of collecting evidence from computer systems to be accepted in a court of law
What does a chain of custody form record?
Where, when, and who collected the evidence, who handled it subsequently, and where it was stored
What is data destruction and disposal?
Destroying or decommissioning data storage media, such as hard disks and flash drives
Fill in the blank: Data from a file ‘deleted’ from a disk is not ______.
erased
What should be done before repurposing or recycling media devices?
Sanitize data remnants on the media
What is the importance of monitoring software licenses?
To ensure compliance with licensing agreements and avoid legal issues
What happens to data when a file is deleted from a disk?
The HDD sector or SSD block is marked as available for writing; the information remains until new data is written over it.
True or False: Using the OS standard formatting tool completely erases all data from a disk.
False
The formatting tool only removes references to files and marks sectors as usable.
What is the purpose of disk erasing/wiping software?
To ensure that old data is destroyed by writing to each location on a hard disk drive.