3.3 Flashcards
Data at rest
is data that has arrived at a destination in a file system, database, or object storage (disk,
tape) and is not being accessed or used
- It typically refers to stored data and excludes data that is moving across a network or is temporarily in computer memory or Redis cache waiting to be read or updated
- Data at rest is data that is not dynamically moving from device to device or network to network
Data in transit
is being packet forwarded or
switched over a wireless or wired network in a unicast, broadcast, multicast, or anycast
fashion
Examples include:
* Wired Ethernet
* Cable (DOCSIS)
* Fiber optic
* 802.11 wireless
* Cellular
* Satellite
* Personal area networking using RFID,
Bluetooth, Infrared, Zigbee, and more
data in use
This is active data undergoing processing, translation, analysis, change, or other manipulation
Examples include:
* Data in system RAM memory
* CPU registers
* Caches and buffers
* Data in Memcached or Redis clusters
* Database transactions
* Cloud-based file or code being modified in real-time
by one or more users
There are five common categories used for data classification in various business and commercial
sectors:
- Public data
- Private data
- Internal data
- Confidential data
- Restricted data
Public data
Public data may be
important, but it is
accessible to the
public
Since this data is
openly shared, it is the
lowest level
Private data
Private data requires a
greater level of security
than public data
It should not be
available for public
access and is often
protected through
common security
measures such as
passwords
internal data
Internal data is usually
limited to employees
only and often has
different security
requirements that
affect who can access
it and how it can be
used
confidential data
This information
should only be
accessed by a limited
audience that has
obtained proper
authorization using
strict identity
management
restricted data
This classification is
reserved for an
organization’s most
sensitive information
Access to this data is
strictly controlled to
prevent its unauthorized
use
regulated data
information that its use and
protection is dictated by a
government agency or third-party
agreements
trade secrets
Any practice or process of a
company that is generally not
known outside of the company
Intellectual property
Creations of the mind, such as
inventions, literary and artistic works, designs and symbols, names, and
images used in commerce
Personal health
information (PHI)
The demographic information,
medical histories, test and lab results, mental health conditions, insurance
information, and other data
Personally identifiable
information (PII)
Any representation of data that allows the identity of an individual to whom the information applies to be
reasonably inferred by either direct or indirect means
Legal information
Involves the careful reading about
specific clauses or stipulations that
does not constitute “advice”