Lesson 9 - Chapter 4: Compliance and Auditing Flashcards
Besides encryption, how else must IT professionals protect data? (3)
- handle it according to its classification
- enforcing user policies so data is handled appropriately in its use (at rest, transit, in use)
- apply classification to other software/hardware resources
What is data classification?
organizing data according to its sensitivity
(for larger organizations, government entities and strict government regulations apply)
What does using classification schemes allow employees/techs to know quickly? (2)
- what to do with documents
- what to do with drives containing documents
What are the 4 types of regulated data?
- Personally Identifiable Information (PII)
- Protected Health Information (PHI)
- Payment Card Industry (PCI)
- General Data Protection Regulation (GDPR)
What is PII?
Personally Identifiable Information
umbrella term for any data that can lead back to a specific individual
What is PHI?
Protected Health Information
any PII that involves a person’s health status, medical records, and healthcare services they received
What is PCI and what does it stand for?
Payment Card Industry
a rigorous set of rules for systems that accept, transmit, process, or store credit/debit card payments
What is GDPR?
General Data Protection Regulation
a new law that defines a broad set of rights and protections for the personal information of citizens living in countries in the European Union
What does compliance mean?
members of a company/organization must comply with all of the rules that apply to that company
(hardware, software, data, network access)
What’s the point of compliance in IT?
designed to stop users with insufficient technical skill or knowledge from installing malicious programs/applications
(keeps technical support calls down)
From a tech’s point of view, what’s the most common compliance issue?
software (what users can install or can’t)
You have a ___ ____ to use software in compliance with its license
legal obligation
How do you access software that released under a commercial license?
you have a legal obligation to pay money to access it
(before you could buy it, use it forever, sell it to someone, or give it away, etc but now it’s different as they want monthly fees)
What does a personal license grant you when you buy a monthly subscription to Microsoft 365?
enables you to share the software with several other people or accounts and use it on several of your personal machines
What does EULA stand for?
End User License Agreement
What is the EULA?
End User License Agreement
you agree when you open or install new software, obliged to use the copyright holder’s sharing guidelines