Assets Security Flashcards
What are the Information Life Cycles
Classification
Categorization
Ownership
Maintenance
Data Classification
helps organization to understand what the data-oriented ramifications of exploitation are
What are the Data Classification labels
Top Secret Secret Confidential Sensitive but unclassified (SBU) Unclassified
What are the Data Classifications Criteria
Value - what is it worth
Age - How current is the information (useful if beyond 5 years?)
Useful life - At what point is it no longer worth protecting
Personal Association - Medical records, personnel files
Examples of regulated data
Card Holder Data (CHD) - cc#, name, expiration
Personally Identifiable Information (PII) - name, address, SSN, DOB
Protect Health Information (PHI) - PII + related health information
What are the roles for Data Ownership
Business/Mission Owner Data (Information) Owner System Owner Custodians Users
What is Business/Mission Owner
Senior Leadership
provide adequate funding and manpower to implement
enforce program policy when needed
What is Data Owner
Also know as Information Owner
Accountable for the data
Determines who can access
What is System Owner
Owns the OS, DB, responsible for the patching etc..
What is Custodians
Hands on to achieve data protection
Performing testing and verifying backup
Data Restoration
What are users of data
Individuals who be granted access to use data as part of their job
What is a Data Controller
creates/manages sensitive data
must legally ensure security of data access by data processor
What is a Data Processor
3rd party that access the organization sensitive data
What is degaussing
applying large magnetic field to erase magnetic media (hard disk)
What is best way to remove data
Degaussing
Destruction