ISC Deck 1 Flashcards
HIPAA Components
Privacy Rule - Standards
Security Rule - Protect/Safeguards
Breach Notifications - Notify, no more than 60 days
Enforcement - civil/criminal punishment
Framework Tiers
Tier 1 - Partial - No integration/formal processes; ad-hoc
Tier 2 - Awareness; basis understanding company-wide but NOT formal
Tier 3 - Repeatable - Formal processes and integration
Tier 4 - Adaptable - Tier 3 plus prioritization of continuous improvement.
HIPAA Covered Entities
Must transmit protected health information (PHI) electronically.
Three Components of NIST Framework
Framework Core (ID, protect, detect, respond, recover)
Framework Tiers -Assess current risk mgmt
Framework Profile - establish baseline for current and find desired.
NIST Privacy Framework Additions
Govern
Control
Communicate
HIPAA for Treatment
Normally PHI should only be the minimum necessary, but for TREATMENT, this does not apply and the provider can view all of it to better understand patient.
GDPR Objectives
Give EU individuals more control over personal data
Harmonize data protection laws across EU
GDPR Rights
Right of Access
Right of Erasure
Right to Object
Right to Data Portability
GDPR Principles
Lawfulness: legal basis, transparent
Purpose Limitation: defined purpose
Data Minimization: minimum necessary data
Storage Limitation: retention
Integrity and Confidentiality
Gateway vs Router
Gateway and routers do similar things in that they transmit packets across networks. Gateways are more advanced in that they translate protocols which is when packets are not in the same format and need to be understood in order to be transmitted.
DSI Layers
Path of data in a network to a receiving device
Application (7): interface with data
Presentation (6): converts data in correct form; encryption
Session (5): communication is established
Transport (4); rules on how data is transferred
Network (3): address to ensure proper destination
Data Link (2): formatted for transmission; data packets
Physical (1): converts to bit
IaaS vs PaaS
Both reduce cap exp, increase scalability of business
IaaS allows control over OS, firewalls and uptime
PaaS is normally focused on one function, which in many cases is developing an application and not having to worry about the underlying infrastructure management.
AIS Audit Trail
Invoice - Journal - Ledger - TB - F/S Reports
Cloud Computing Deployment Models
Public
Private
Hybrid
Community - purpose is to share with industry peers
Disaster Recovery Plan
Focus on IT disruptions
1. Assess Risk
2. ID
3. Develop
4. Determine Responsibilities
5. Test