Governance, Risk, and Compliance Flashcards
MTTR
Mean Time To Repair
a measure of time taken to correct a fault to restore the system to full operation
often used to describe the average time to replace or recover a system or product
Mission Essential Function
things that must be performed by an organization to meet its mission
MTBF
Mean Time Between Failures
average time between system breakdowns
crucial maintenance metric to measure performance, safety, and equipment design
can also be used to determine the reliability of an asset
Data Ownership Roles
- Data Owner
- Data Steward
- Data Custodian
- Privacy Officer
SPI
Sensitive Personal Information
information about a subject’s opinions, beliefs, and nature afforded specially protected status by privacy legislation
GLBA
Grmm-Leach-Bliley Act
a U.S. law that requires financial institution to explain how they share and protect their customers’ private information
Risk Severity = ? * Impact
Likelihood of occurrence
DPO
Data Protection Officer
They oversee the organization’s data protection strategy and implementation, and make sure that the organization complies with the GDPR
SLA
Service Level Agreement
defines the level of service the customer expects from the service provider
the level of service definitions should be specific and measurable in each area
MOU
Memorandum of Understanding
a legal document that describes a mutual agreement between parties
ISA
Interconnection Security Agreement
an agreement that specifies the technical and security requirements of the interconnection security requirements of the interconnection between organizations
BPA
Business Partnership Agreement
a legal agreement between partners
establishes the terms, conditions, and expectations of the relationship between the partners
Data Custodian
A custodian configures data protection based on security policies
Data Owner
Data owners assign labels such as top secret data
RPO
Recovery Point Objective
specifies the allowable data loss
the amount of times that can pass during an interuption before the quantity of data lost during that period surpasses business continuity planning’s maximum threshold