28. Data Security Frameworks Flashcards

1
Q

Data Security Frameworks

Deciding which controls we want to use, apply and how we deploy them

A
  1. Baselines
  2. Scoping
  3. Tailoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Data Security Frameworks

Different controls for different data

A
  1. Data at rest
  2. Data in transit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data Security Frameworks

Scoping

A

Determin which portion of a standard we want to deploy

  • Take portions of the standard we want to apply
  • determine the scope and what is out of scope
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data Security Frameworks

Tailoring

A

Customize the standard to our organisation and needs

  • We may apply the standard but choose to use a stronger encryption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Security Frameworks

Certification

A

System and security measured protecting it meet the security requirements set out by the owner or by law

  • If owner refuses certification, you need to work with data owner to address concerns
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data Security Frameworks

Accreditation

A

Data owner accepts certification and residual risk
Required before system put into production

How well did you know this?
1
Not at all
2
3
4
5
Perfectly