Legal and Compliance Flashcards
What is the Cloud Act
Mandates how long electronic communications are kept for such as telephone records etc. The cloud act extends this to cover data stored outside of the US. It prohibits US companies not complying with a data request or warrant by claiming the data is stored outside of the US. It places the responsibility on the company on providing some means of access that is in the US - duplicate copies.
What is FedRamp ?
US Federal act detailing the best practice for getting into the cloud.
When does chain of custody start ?
As soon as the term evidence is used
What is the main problem with forensics in the cloud ?
Locating where the data is
What is Virtual Machine Inspection ?
Software on hypervisor that allows you to inspect a running vm memory.
What is the first step in e-discovery
identification
What are the seven steps to e-discovery ?
Identification, Preservation, Collection,Processed,Review,Production,Presentation
What stage of e-discovery is legal hold enforced ?
Preservation
List the volatility order for evidence collection ?
Screen
RAM
Cache
Storage Drives
What are the three types of case e-discovery could be used for ?
Operational, Civil and Criminal
What is risk appetite ?
The amount of risk in terms of amount and money an organisation is willing to take on
What is risk profile ?
How well or not an organisation can withstand risk events
What is risk tolerance ?
For any particular risk event it is the positive or negative variance around our usual risk choice