CISSP Domain 2: Managing Data Lifecycle Flashcards
What are data roles?
different responsibilities and roles associated with the management and protection of data assets within an organization
What are the different data roles?
- Data Owner
- Data Controller
- Data Custodian
- Data Processor
- Data Users/Subjects
Describe data owner and their key responsibilities
- typically a senior-level individual within an organization who has the ultimate responsibility for a specific set of data assets
- key responsibilities of a data owner include:
- determining the classification and sensitivity of data
- establishing and communicating data handling and usage policies
- authorizing access rights and permissions for data
- ensuring compliance with relevant laws, regulations, and contractual obligations
- reviewing and approving requests for data access or changes to access permissions
- collaborating with other stakeholders to establish data governance strategies
Describe Data Controller and their key responsibilities
- entity or organization that determines the purposes, conditions, and means of processing personal data
- key responsibilities of a data controller include:
- identifying the legal basis and purpose for data processing
- implementing appropriate data protection policies and procedures
- ensuring data processing activities align with data subject rights and consent requirements
- maintaining records of data processing activities and associated documentation
- assessing and managing data privacy risks and impact assessments
- coordinating with data processors and other stakeholders to ensure compliance
Desctibe Data Custodian and their key responsibilities
- responsible for the technical implementation, management, and protection of data assets
- handle the day-to-day operations of data storage, access, and maintenance
- key responsibilities of a data custodian include:
- implementing and managing technical controls for data protection, such as access controls, encryption, backups, and data retention policies
- ensuring data integrity, availability, and confidentiality
- monitoring and auditing data access and usage
- implementing and maintaining data backup and recovery mechanisms
- managing user accounts and access privileges to data systems
- collaborating with data owners and users to enforce data handling policies
What are the stages of data lifecycle?
Name from the beginning
- Data Collection
- Data Analysis
- Data Usage
- Data Retention
- Data Destruction
Admin asked to scrub data to remove data that is no longer needed by an organization is what phase of the data lifecycle?
data maintenance
What is the entity assigned specific responsibility for a data asset in order to ensure its protection for use by the organization?
data owner