Módulo 13 - Data Protection and Compliance Flashcards
List:
Impacts of non-compliance with data protection laws
- Legal sanctions
- Financial penalties
- Legal liabilities
- Reputational damage
- Loss of customer trust
- Increased regulatory scrutiny
List:
Consequences of a data or privacy breach
- Reputation damage
- Identity theft
- Fines
- Intellectual property (IP) theft
- Escalation risks
List:
Notifications required in data breaches
- Regulator
- Law enforcement
- Affected individuals
- Third-party companies
- Public (media or social channels)
List:
Impacts of contractual non-compliance
- Breach of contract
- Termination of contracts
- Indemnification and liability
- Non-compliance penalties
List:
Forms of non-compliance with software licensing
- Exceeding permitted installations
- Unauthorized sharing
- Unauthorized usage
- Modifying code
- Distributing software without authorization
Define:
Security compliance
Adherence to standards, regulations, and practices to protect sensitive data.
Define:
Sanctions
Penalties for non-compliance with laws or rules.
Define:
Data breach
Unauthorized reading, modification, or deletion of data.
Define: Privacy breach
Loss or disclosure of personal and sensitive data.
Define:
Escalation in data breaches
Raising the issue to senior decision-makers for legal and regulatory assessment.
Define:
Indemnification in contracts
Shifting liability for damages or legal costs to another party.
Define:
Non-compliance penalties
Fines or damages stipulated in contracts for failing cybersecurity measures.
Define:
License remediation
Correcting non-compliance with software licenses.
List:
Types of regulated data
- Financial information
- Healthcare records
- Social security numbers
- Credit card details
- Personally identifiable information (PII)
List:
Types of human-readable data
- Text
- Images
- Multimedia content
- Documents
- Reports
- Emails
- Presentations
List:
Types of non-human-readable data
- Binary code
- Encrypted data
- Machine-readable formats
- Complex structured data
- Encoded information
List:
Security measures for non-human-readable data
- Encryption
- Access controls
- Intrusion detection and prevention
- Secure data exchange
- Code/application security
List:
Data classification levels based on confidentiality
- Public (unclassified)
- Confidential (secret)
- Critical (top secret)
List:
Data classification levels for government and military
- Unclassified
- Sensitive
- Confidential
- Secret
- Top Secret
- Top Secret Compartmentalized
List:
Examples of private/personal data
- Names
- Addresses
- Social security numbers
- Financial information
- Login credentials
- Biometric data
- Health records
List:
Categories of proprietary data
- Intellectual property (IP)
- Trade secrets
- Product information
- Service information
Define:
Data types
Categorization of data based on characteristics and use.
Define:
Regulated data
Data subject to legal and regulatory requirements for handling and protection.
Define:
Trade secrets
Confidential information giving a business a competitive advantage.
Define:
Human-readable data
Data easily understood by humans, such as text and images.
Define:
Non-human-readable data
Data requiring specialized software to interpret, such as binary or encrypted formats.
Define:
Data classification schema
A system to label data based on confidentiality and type.
Define:
Proprietary information
Nonpublic data owned by a company, like intellectual property.
Define:
Restricted data
Highly confidential data with stringent access controls.
Acronym:
PCI DSS
Payment Card Industry Data Security Standard
Acronym:
PII
Personally Identifiable Information
List:
Examples of privacy data
- Names
- Addresses
- Contact information
- Social security numbers
- Medical records
- Financial transactions
List:
Examples of confidential data
- Trade secrets
- Intellectual property
- Financial statements
- Proprietary algorithms
- Source code
List:
Rights of data subjects under GDPR
- Right to access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
List:
Impacts of privacy laws on data inventories and retention
- Maintaining detailed records
- Identifying legal grounds for processing
- Ensuring data minimization
- Defining retention periods
- Responding to data subject requests
- Implementing robust security measures
List:
Responsibilities of data processors under GDPR
- Process data only as instructed by the controller
- Implement appropriate security measures
- Maintain confidentiality and integrity of data
- Keep records of processing activities
- Cooperate with data controllers
List:
Responsibilities of data controllers under GDPR
- Define purposes and means of processing
- Obtain consent from data subjects
- Provide privacy notices
- Implement data protection policies
- Handle data subject requests