2.2 Establish Information and Asset Handling Requirements Flashcards

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are Asset Handling Requirements?

A

Clear procedures that mitigate risks like asset misplacement or handling by clearly defining proper handling of the valued asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What should be included in an Asset Classification Policy to ensure valued assets are handled properly?

A

Asset Handling Requirements | Handling Procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False:
Asset Handling Requirements are driven by the Assets Classification and Assets Media type.

A

FALSE: Asset handling requirements should be specific to the asset classification level and ignores the media type. | Example: A CD being transported with sensitive Information should follow the same handling requirements as a USB or Person with sensitive information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Asset Owners are always accountable for the protection of assets. What two things much an owner convey regarding Asset Handling to ensure Asset Classficiation Policies are met?

A

Only designated individual should have access to sensitive Media | Owners must define who is authorized to access the media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Regarding storage of media, how should Top-Secret data be stored on a digital device?

A

With robust encryption, such as AES-256, and should be stored physically in a secure location safe from unauthorized access, high-humidity, or other risks that could threatent the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Regarding Media Retention and Destruction, what can influence an organization’s handling of data beyond retention and destruction in line with their personal classification procedures?

A

Auditory and Regulatory compliance frameworks. | For example, Payment Card Industry Data Securtiy Standard (PCI DSS) dictates audit logs most be stored for no less than a year and all logs created in the last 90-days must be available for immediate analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When should credit card data be destroyed in regards to PCI DSS standards?

A

Immediately as soon as the data is no longer required for data or legal information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly