Data Protection Flashcards
Data Protection
process of safeguarding data from corruption, compromise, and/or loss
Data Classification
category based on the organizations value and sensitivity if the data was disclosed
Sensitive Data
anything that results in loss of security or advantage to a company
Data Ownership
person who handles the confidentiality, integrity, available, and privacy of data
Data Owner
highest role w/ the responsibility for maintaining the state of the data
Data Controller
holds responsibility for deciding the methodology of data control and legal ramifications
Data Processor
group or individual hired by a data controller to help with working his method
Data Steward
focused on the quality of data and the associated metadata
Data Custodian
responsible for handling the management of the system
Privacy Officer
role that is responsible for the oversight of any privacy related data
Data at Rest
any data stored in databases, file systems, or a storage solution
Full Disk Encryption (FDE)
encrypting the data at rest
Partition, File, Volume, Database, Record
encryption
Data in transit
as stated
Secure Sockets Layer (SSL) & Transport Layer Security (TLS)
cryptographic protocols designed to provide secure communications over a network
Internet Protocol Security (Ipsec)
protocol collection used to secure IP connections by authentication and encrypting each IP packet
Data Types
Regulated, Personal Identification Information (PII), Protected Health Information (PHI), Trade Secret, Intellectual Property, Legal/Financial Information
Data Sovereignty
digital information is subject to the laws of the country its located at
General Data Protection Regulation (GDPR)
European union strict rules for data protection and grants individuals strong rights over their data
Encryption
transform plain text data to cipher text using an algorithm and key
Hashing
turns data into a fixed size of numerical and/or alphanumeric characters
Masking
replacing same or all of the data with a placeholder
Tokinization
replaces sensitive data with non-sensitive
Obfuscation
making data unclear or unintelligible to unauthorized individuals