28. Data Security Frameworks Flashcards
1
Q
Data Security Frameworks
Deciding which controls we want to use, apply and how we deploy them
A
- Baselines
- Scoping
- Tailoring
2
Q
Data Security Frameworks
Different controls for different data
A
- Data at rest
- Data in transit
3
Q
Data Security Frameworks
Scoping
A
Determin which portion of a standard we want to deploy
- Take portions of the standard we want to apply
- determine the scope and what is out of scope
4
Q
Data Security Frameworks
Tailoring
A
Customize the standard to our organisation and needs
- We may apply the standard but choose to use a stronger encryption
5
Q
Data Security Frameworks
Certification
A
System and security measured protecting it meet the security requirements set out by the owner or by law
- If owner refuses certification, you need to work with data owner to address concerns
6
Q
Data Security Frameworks
Accreditation
A
Data owner accepts certification and residual risk
Required before system put into production