Domain 2 - Asset Security Flashcards
What is the purpose of classification?
To ensure that information/assets are marked in such a way that only those with an appropriate level of clearance can have access to them.
What is categorization?
The process of determining the impact of the loss of confidentiality, integrity, or availability of the information/assets to an organization.
Define Quality Control (QC)
Based on INTERNAL standards established to control and monitor quality
Define Quality Assurance (QA)
Based on EXTERNAL standards and involves reviewing activities and processes to ensure final products meet standards of quality.
What is a ‘data owner’?
MASTER of all
Understand the replacement cost of the info
Determine who has a need for the data
Identify when data needs to be destroyed
What is a ‘data processer’?
MANAGER of all (on behalf of the data owner)
Ensure accessibility
Ensure ongoing integrity
Clearing vs Purging data?
Clearing is the removal of sensitive info so that it can’t be reconstructed using NORMAL system functions or techniques
Purging is the removed of sensitive data with the intent that the data cannot be reconstructed by ANY KNOWN technique