Domain 2 - Asset Security Flashcards
What is Data Remanence?
Data remanence is the data that remains on media after the data was supposedly erased.
What does a degausser do?
It removes information from media by generating a strong magnetic field
What does Erasing media mean?
Erasing media is simply performing a delete operation against a file, a selection of files or the entire media.
What does Clearing media mean?
Cleaning or overwriting is a process of preparing media for reuse and ensuring that the cleared data cannot be recovered using traditional recovery tools
What does Purging media mean?
Purging is a more intense form of cleaning that prepared media for reuse in less secure environments
What is Declassification?
Declassification involves any process that purges media or a system in preparation for reuse in an unclassified environment.
What is the catch with L2TP?
L2TP transmits data in cleartext, but L2TP/IPsec encrypts data and sends it over the internet using tunnel mode to protect it while in transit.
What are the responsibilities of the Data Owner?
The Data Owner is the person who has ultimate responsibility for the data. They establish the rules for appropriate use, provides input on security requirements, decide who has access, and assists in the identification and assessment of the common security controls.
What are the responsibilities of the Asset Owners?
The asset owner (or system owner) is the person who owns the asset or system that processes sensitive data. They maintain the system security plan and ensure that personnel receives appropriate security training.
What are the responsibilities of the Data Processors?
The data processors process personal data on behalf of the data controller (owner).
What is the penelty for GDPR?
4% of global revenue or 20 euro, which ever is higher
What is Pseudonymization?
Replacing data with articifial identifiers (such as pseudonyms.
What is Tokenization?
Tokenization uses tokens to represent other data.
What are the responsibilities of the Data Administrators?
A data administrator is responsible for granting appropriate access to personnel.
What are the responsibilities of the Data Custodians?
Data owners often delegate day-to-day tasks to a custodian