Domain #2: Asset Security Flashcards
What is an “Asset”?
An asset is, anything of worth to an organization. This includes people,
partners, equipment, facilities, reputation, and information
Information Life Cycle
*Acquisition
*Store
*Use
*Share
*Archival
*Disposal
Commercial/Private Information
Classification:
*Confidential
*Private
*Sensitive
*Public
Military Information Classification
*Top Secret
*Secret
*Confidential
*Sensitive but unclassified
*Unclassified
Data Classification Procedure/Steps
- Define classification levels
- Criteria for how data is classified
- Data owner should classify under their responsibility
- Identify data custodian who will maintain data and security
- Indicate security controls or protection for each classification
- Document any exceptions
- Indicate process for transferring ownership to different custodian
- Define procedure for declassifying data
- Integrate in security awareness training program
What are the responsibilities of the CEO?
*CEO – Chief Executive Officer
*Day-to-day management of entire organization
*Often Chairperson of the Board of Directors and is highest
ranking officer in company
*Oversees companies finances, budget, strategic vision, business
plan
*Decides on partnerships with other vendors
*Decides how company will differentiate itself from its competitors
What are the responsibilities of CFO?
*CFO – Chief Financial Officer
*Day-to-day account and financial activities
*Responsible for overall financial structure
*Determines companies current and future financial needs
*Maintains company capital structure
*Equity, Cash, Credit, Debt
*Oversees budget and financial performance metrics
*Responsible for filing financial statements to regulatory bodies
What are the responsibilities of CPO?
*CPO – Chief Privacy Officer
*Reports to Chief Security Officer
*Newer position
*Oversee appropriate handling and usage of data
*Familiar with outside regulations
and market specific legal requirements
*Usually an attorney by training
What are the responsibilities of CSO?
CSO – Chief Security Officer
*Responsible for understanding company specific risks and processes used to mitigate these risks
*Must understand business drivers
*Responsible for maintaining company Security Program
*Responsible for compliance with applicable regulations and laws
*Ensures Business is NOT interrupted in any way
What are the responsibilities of CISO?
*Chief Information Security Officer
*Must have a strong understanding of business processes and objectives
*Ability to communicate effectively with upper management
*Understand legal regulations and security frameworks
*Develop and maintain security awareness programs
*Develop security budget and report to Board of Directors or upper management
*Respond to security incident or breach
Internal and external labeling of each piece of media in the library should include
*Date created
*Retention period
*Classification level
*Who created it
*Date to be destroyed
*Name and version
What aimed at preventing the loss of sensitive information?
Data leak prevention (DLP) aimed at preventing the loss of sensitive information