Data Classification and Protection Flashcards

1
Q

Data Classification

A

The undertaking of developing levels of sensitivity for information and assigning those levels for the purpose of establishing appropriate modes of protection for those data sets.

The formal data classification program consists of:
- sensitivity levels
- Marking procedures
- Access procedures
- Handling procedures
- Destruction procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Sensitivity Levels

A

In a data classification program, a set of sensitivity levels is established, which reflects the nature of data that is used in the organisation. For example:
- Top secret
- Secret
- Confidential
- Restricted
- Official
- Unclassified
- Public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Information Labelling

A

The process of affixing a word, symbol or phrase on a set of data. The purpose of labelling is to make other readers aware of the level of classification on a set of data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Information Handling

A

Handling guidelines need to be developed for each level of classification, for each possible activity, including:
- Computer storage
- computer access control
- Backup tape and other portable media
- Network transmission
- facsimile
- Printing
- Mailing/shipping/courier
- carrying
- Hard copy storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Destruction

A

Classification guidelines need to include information on the proper disposal of classified information.

Destruction procedures are steps to ensure that information is discarded in a way that renders it non-retrievable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Certification

A

The process of evaluation a system against a set of formal standards, policies or specifications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Accreditation

A

The formal approval for the use of a certified system for a defined period of time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Internal Audit

A

The activity of self-evaluation of security controls and policies to measure effectiveness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly