CCSP Domain 6 : Legal Hold and eDiscovery Flashcards

1
Q

What does e-discovery typically involve?

A

identification, collection and production of data related to a case and legal holds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the recommended action for a business when it faces a need for eDiscovery activity?

A

hiring an expert consultant who is licensed for this purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is eDiscovery (electronic Discovery)?

A

process of identifying and obtaining electronic evidence for either prosecutorial or litigation purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the tools that aid with the process of eDiscovery?

A
  1. some cloud providers offer SaaS eDiscovery solutions in the form of cloud-based applications that can perform searches and collection of pertinent data (provider’s own cloud data center for its own customers)
  2. host-based tools that can be used to locate applicable information on specific machines (both HW and virtualized)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the most significant barrier to eDiscovery efforts in organizations that make heavy use of many different cloud services?

A

coordinating multiple providers that might have relevant records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

I Preserve Collected Policies Rendered Absolutely Pointless

What are the seven main steps for eDiscovery?

A
  1. ESI identification
  2. preservation
  3. collection
  4. processing
  5. review
  6. analysis
  7. production
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The Cloud Security Alliance points to a number of key areas to consider during e-discovery. What is most likely to drive higher costs in a cloud environment when the organization is operating under a litigation hold?

A

storage duration; cloud storage is typically billed by quantity and time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the first concern for discovery and legal hold scenarios?

A

identify the data that the hold request or discovery requires

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What do legal holds require organizations to do with relevant data?

A

identify and preserve data that meets the hold’s scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Organization preserved data due to a legal hold, but the data has hit the end of its retention timeframe due to statutory requirements. What should be done to the data?

A

continue to preserve the data to meet the legal hold requirements - legal holds normally take precedence over other deletion requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why is a legal hold drive for retention process?

A

because it may require deviation from the organizational’s normal process for data retention and destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When does a legal hold typically occur?

A

organization is notified that either (a) law enforcement or regulatory entity is commencing an investigation or (b) private entity is commencing litigation against the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What organizational policy often accounts for legal holds?

A

retention policies often include language that addresses legal holds because holds can impact retention practices and requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

eDiscovery is specifically intended to ensure compliance with what?

A

ensure compliance with litigation hold obligations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the initial phase of eDiscovery process?

A

legal hold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does ESI stand for?

A

electronically stored information

17
Q

When is eDiscovery is commonly used?

A

when there is a civil litigation to gather evidence for both plaintiffs and defendants

18
Q

What happens during the Production phase of eDiscovery?

A

relevant ESI is produced in a format suitable for legal proceedings, regulatory submissions, or investigations

19
Q

Which ISO standard provides guidance for eDiscovery programs?

A

ISO 27050

20
Q

What are the e-discovery challanges/complexities in the cloud?

A
  1. organization investigating an incident may lack the ability to compel the CSP to turn over vital information needed to investigate
  2. information may be housed in a country where jurisdictional issues make the data more difficult to access
  3. maintaining a chain of custody is more difficult since the are more entities involved in the process
21
Q

Before migrating to cloud, at what phase should be eDiscovery considered as a security requirement?

A

when considering a cloud vendor, during the selection and contract negotiation phases; otherwise CSP may not cooperate to aid with eDiscovery

22
Q

What are important considerations for eDiscovery in the cloud that can be handled proactively?

A

data residency and system architecture - such as when designing or deploying a system or business process

23
Q

Why is the burden of recording and preserving potential evidence shift to the customer?

A

CSPs may not preserve essential data for the required period of time to support historical investigations; they may not even log all the data relevant to support an investigation

24
Q
A