Data Classification Flashcards
Who is the data owner ?
The data owner is the organisation that has collected or created the data. Normally assigned to an individual such as a department head. In the cloud the cloud customer is the data owner.
What duties does a data custodian perofrm ?
The data custodian is entrusted by the data owner to secure the data as well as daily administration and maintenance of the data.
What is the role of the data processor ?
The data processor is anybody who manipulates, copies, prints or destroys the data on behalf of the data owner
Who is ultimately responsible for data ?
Data owner
Does the data processor always have to have a direct link to the data owner ?
No
What are the stages of the data lifecycle ?
Create, Store, Use, Share, Archive, Destroy
What are the ways data can be categorised?
Functional Unit
Business Unit
Project
Regulatory
Who classifies the data and when is it done ?
Data Owner in create phase
What is data labelling ?
Labelling data from a security perspective makes sense by readily indicating the nature of certain information and how it should be handled and protected.
Common Labels are
Date of Creation
Date of scheduled destruction
Confidentiality
Handling directions
Dissemination
Source
Jurisdiction
Applicable Regulation
What is Data Discovery
Data Discovery relates to several techniques that an organisation utilizes to get a handle on its data architecture for either an investigation or creating an initial inventory.
What are the three main types of data discovery ?
Labels, Content and Metadata
Name four ways to categorise data ?
Regulatory, Business Function, Functional Unit, Project
Name three ways to classify data ?
Sensitivity, Jurisdiction, Criticality
Give examples of some common data labels ?
Date of Creation
Date of Destruction
Confidentiality Level
Handling Directions
Disesemination
Access Limitation
Source
Jurisdiction
Applicable Regulation
Name five data discovery methods ?
Label, Metadata, Content, Structure, Analytics
What are the jurisdictional requirements of Asia ?
Data privacy differs greatly between countries - Japan adheres to EU model as does Singapore China on the other had demands that all IT traffic and communications be accessible to the Chineses Government.