Domain 2 Flashcards
Accountability
Accountability ensures that account management has assurance that only authorized users are accessing the system and using it properly.
Asset
Anything of value that is owned by an organization. Assets include both tangible items such as information systems and physical property and intangible assets such as intellectual property.
Asset Lifecycle
The phases that an asset goes through from creation (collection) to destruction.
Baseline
A documented, lowest level of security configuration allowed by a standard or organization.
Categorization
The process of grouping sets of data, information or knowledge that have comparable sensitivities (impact or loss ratings), and have similar security needs mandated by law, contracts or other compliance regimes.
Classification
The process of recognizing the impacts to the organization if its information suffers any security compromise—to its confidentiality-, integrity-, availability-, non-repudiation-, authenticity-, privacy- or safety-related characteristics. Classifications are derived from the compliance mandates the organization must operate within, whether these be law, regulation, contract-specified standards or other business expectations.
Clearing
The removal of sensitive data from storage devices in such a way that there is assurance the data may not be reconstructed using normal system functions or software recovery utilities.
Data Custodian, Custodian
The individual who manages permissions and access on a day-to-day basis based on instructions from the data owner. Responsible for protecting an asset that has value, while in the custodian’s possession.
Defensible Destruction
Eliminating data using a controlled, legally defensible and regulatory compliant way.
Inventory
Complete list of items.
Purging
The removal of sensitive data from a system or storage device with the intent that the data cannot be reconstructed by any known technique.
Qualitative
Measuring something without using numbers, using adjectives, scales or grades.
Quantitative
Using numbers to measure something, usually monetary values.
Recovery
The process of jointly addressing business resiliency and restoration of critical infrastructure and functionality after a disruption.
Responsibility
Obligation for doing something. Can be delegated.