Module 16 Flashcards

1
Q

What is GDPR?

A

enacted by the EU to harmonise all the data protection laws used across Europe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is GDPR embedded in UK law?

A

by the data protection act 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who is responsible for protecting data?

A

the information commissioners office (ico) who is an independent authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

who enforces information laws in Scotland?

A

Scottish information commissioners office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who does GDPR apply to?

A

any business or organisation which uses information for any business of non household purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is processing information under GDPR?

A

collecting, recording, storing, disclosure or other use of personal data by the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who must have a Data protection officer?

A

organisation how regularly process data or those in the public sector who deal with large amounts of personal info e.g. the NHS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the EU directive that led to GDPR require of personal data?

A
  • processed in a fair and legal manner
  • for a purpose
  • not excessive
  • accurate
  • current
  • kept no longer than deemed necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What rights to EU citizens have regarding their data?

A
  • access data
  • correct, erase, o block info
  • object to usage
  • oppose automated decisions
  • judicial remedy and compensation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What fine can be charged for data breaches?

A

up to 17 million or 4% of global turnover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What must companies do if there has been a data breach?

A

Reveal this, even if only one company is affected. They have 72 hours to report a breach to the ICO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How can you identify a user?

A
  • something you have e.g. token
  • something you know e.g. PIN
  • something you are e.g. thumbprint, signature, face id
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the simple changes to protect info?

A
  • passphrases not words, or even better, Touch ID
  • lock all devices
  • access controls
  • update all software
  • dont use work laptop for personal reasons
  • firewalls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can individuals protect the information?

A
  • Anti theft devices
  • avoid public wifi
  • check web addresses for security, https
  • be cautious about sharing on social media
  • turn off location services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a denial of service attack?

A

malicious attack with the intent of restricting the operation of the server. flood communication ports and memory of a target site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a virus?

A

program or piece of code that is loaded onto a computer without the knowledge of the user and runs without the knowledge of the user. They can also replicate themselves.

17
Q

What is spyware?

A

malicious software designed to monitor or capture actions by a valid computer user.

18
Q

What controls can an organisation use to prevent spam?

A

anti span programs
email authentication eg digital signature
train staff

19
Q

What is cloud computing in relation to DRP?

A

-storing all info on the cloud so that info can be processed from any location

advantages- recovery is rapid

dis

  • dependent on third party cloud host
  • no opportunity to recovery hardware
20
Q

What is a mutual aid pact?

A

agreement between two or more companies share resources in the case disaster

advantages- no cost
dis -need capacity and compatible platforms
-trust
-what if everyones impacted by the same disaster?

21
Q

What is a cold site (crate and ship)?

A

lease a building space and design it t hold computer equipment. equipment is not stored here but there is an agreement with a crate and ship vendor.

ad- easy to implement due to crate and ship vendor experience

  • cheaper than hot site
  • more convenient than mutual aid

dis - can be slow

  • may not host all the parties who want to use it
  • vendor might not be reliable if the have multiple customers
22
Q

What is a hot site?

A

fully functioning, fully equipped disaster recovery room. mirroring is used to back up data.
advantages - ready to go since mirrored
dis- highest cost
-needs to be maintained
-may not have room if used by lots of companies