Governance, Risk , Compliance Flashcards
DSAR
Data Subject Access Requests
Must be executed without undue delay and at the latest, within one month of receipt
GDPR
General Data Protection Regulation
DPO
Data Protection Officer
CIS CSC
Centre for Internet Security Critical Security Controls
NIST RMF
National Institute of Standards and Technology Risk Management Framework
Mandatory for US Federal data
ISO/IEC 27001
Standard for an information security management system (ISMS)
ISO/IEC 27002
Code or practice for information security controls
ISO/IEC 27701
Privacy information management systems (PIMS)
ISO 3100
International standards for risk management practices
CCMP
Counter Mode Cipher Block Chaining Message Authentication Code Protocol
Used in WPA2 and uses Advanced Encryption Standard (AES)
WPA3
Wi-Fi Protected Access v3
Requirement to be supported since 2018.
Added network authentication over WPA2
SAE replacing pre shared keys.
And perfect forward secrecy
SAE
Simultaneous Authentication of Equals
Perfect Forward Secrecy
Process changes encryption keys on an ongoing basis
ISO 3100
Covers Risk management
MSA
Master Service Agreement
Umbrella contract for work a vendor does over a period of time