CISSP Domain 2 Flashcards
Information lifecycle
Creation
Classification
Storage
Usage
Archive
Destruction
Data classification and damage level
Value of data by labeling
Top secret: Gracve damage
Secret: Serious damage
Confidential: Damage
Unclassified : No damage
Data classification non governmental
Confidential or Proprietary - Grave damage
Private - Serious damage - PII or PHI
Sensitive - Damage - IP address, OS, software
Public - No damage
Data States
Data at rest - Strong symmetric encryption
Data in transit - combo
Data in use -
Steps in Data management
Define data
Asset classification
Define security requirements
Identify security controls to implement
Establishing information and asset handling requirements
Data maintenance
DLP: Network and Endpoint
Marking sensitive data and assets: Tags and meta tags
Handling assets and data
Data collection limitation
Data location: Data center and redundancy
Storing sensitive data
Data destruction
Eliminating data remnanence
Ensuring appropriate data and assets retention
Data destruction
Data remnanence
Left over data after supposedly erased
Slack space
Unused space within disk cluster
Degausser and SSD
Heavy magnetic field and effective only in magnetic media
Does not effect cd, dvd and SSD
SSD include built in earse command
Erasing
Delete operations in file but actual data remains on drive
Clearing
Overwrite for reuse and ensure clear data cannot be recovered and three separate phases
First character
Complement
Seperate bits
Purging
A level of assurance that data is not recoverable
Repeat clearing process several times
But not always trusted
Destruction
Most Secure method for sanitizing
Cryptographic erasures
If data is encrypted then crypto shed to destroy
They only destroy encryption key and decryption keys but data remains encrypted
Better overwrite the data just in case if encryption isn’t strong
Especially cloud destroy cryptography keys
Retention policies (lawsuit)
Cannot delete potential evidence after a lawsuit is filed however if retention policy dictates it’s legal to delete