Domain 5: Governance, Risk, and Compliance Flashcards

1
Q

What is risk management?

A

Risk management is the process of identifying, assessing, and mitigating risks to an organization’s assets, operations, and data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a security policy?

A

A security policy is a formal document that outlines an organization’s security expectations, responsibilities, and requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is GDPR (General Data Protection Regulation)?

A

GDPR is a regulation in the European Union that governs data protection and privacy for individuals, requiring organizations to protect personal data and uphold privacy rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is PCI DSS (Payment Card Industry Data Security Standard)?

A

PCI DSS is a set of security standards designed to protect cardholder data and ensure the secure processing, storage, and transmission of credit card information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is data classification?

A

Data classification is the process of categorizing data based on its sensitivity and criticality to the organization, determining the level of protection required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly