5.4 - 5.5 Flashcards

1
Q

Risk managment types

A

Legacy systems, internal external threats or multiple parties , ip theft, etc

Acceptance - thats life we will accept the risk
Risk avoidance- use alternative devices
Transference - like cybersec insurance
Sec hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Evaluating risk

A

Risk register
Risk matrix (heatmap)
Inherent risk
Residual risk
Risk appetite

Find and fill gaps with a formal security audit or self assessment add more sec controls for high levels of risk areas like firewalls so now required compliance is every year

Risk awareness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Business impact analysis

A

Recovery time Objective rto when back up

Recovery point objective at what point to turn on rpo

Mean time repair mttr time to fix

Mean time between failures mtbf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Functional recovery plan

A

Plan from outage to back up running, contact of key players, full technical process and list of steps, then test system, then resume

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Privacy impact assessment pia

A

How new products will affect customers data and privacy and this process can be public to build trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data classification

A

Label sensitivity for diff documents requiring different levels of protection information

Proprietary
Personably identifiable information
Protected health information

Public/unclassified
Private/classified/ restricted/internal use
Sensitive
Confidential
Critical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Enhancing privacy

A

Tokenization
Data minimization
Data masking
Anonymization
Pseudo anonymization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data roles

A

Data owner
Data controller
Payroll controller
Data steward
Data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly