Data Protection Flashcards
Data classification
Based on the value to the organization and the sensitivity of the information,
determined by the data owner
Commercial Business Classification Levels
- Public
- Sensitive
- Private
- Confidential
- Critical
Government Classification Levels
- Unclassified
- Sensitive but Unclassified
- Confidential
- Secret
- Top Secret
Data Owner
A senior executive responsible for labeling information assets and ensuring they
are protected with appropriate controls
Data Processor
A group or individual hired by the data controller to assist with tasks like data
collection and processing
Data Controller
Entity responsible for determining data storage, collection, and usage purposes
and methods, as well as ensuring the legality of these processes
Data Steward
Focuses on data quality and metadata, ensuring data is appropriately labeled and
classified, often working under the data owner
Data Custodian
Responsible for managing the systems on which data assets are stored, including
enforcing access controls, encryption, and backup measures
Privacy Officer
Oversees privacy-related data, such as personally identifiable information (PII),
sensitive personal information (SPI), or protected health information (PHI),
ensuring compliance with legal and regulatory frameworks
PII
Personally Identifiable Information
SPI
Sensitive Personal Information
PHI
Personal Health Information
Data Ownership Responsibility
The IT department (CIO or IT personnel) should not be the data owner; data
owners should be individuals from the business side who understand the data’s
content and can make informed decisions about classification
Data at Rest
Data stored in databases, file systems, or storage systems, not actively moving
Encryption Methods for data at rest
- Full Disk Encryption (FDE)
- Partition Encryption
- File Encryption
- Volume Encryption
- Database Encryption
- Record Encryption