Planning and Engagement Flashcards
The process, tools, and strategies that organizations use to address compliance with industry regulations, enterprise risk management, and internal governance.
Governance, risk, and compliance (GRC)
The concept of limiting access to data based on need to know
Confidentiality
A legal concept that addresses what rights an individual has to control how their personal information is used, collected, and disclosed
Privacy
Generally data that allows identification of one individual over other individuals
Personally identifiable Information (PII)
Similar to PII, but applies to data that was created or used in health care context
Protected Health Information (PHI)
Specific to PCI-DSS, this type of PII is specifically related to cardholders
Cardholder Data (CHD)
What is the General Data Protection Regulation (GDPR)?
A law passed within the European Union that imposes data privacy and security obligations on organizations that collect or target data related to people in the EU.
What is PCI-DSS?
A series of rules that businesses that process payments using payment cards should follow tin order to better secure card data and transactions.
What is the goal of PCI-DSS testing?
Security of storage, transmission, and retention of CHD by data processors.
What kinds of agreements are mutual and enforceable by law, requiring an authorized representative from each party to sign?
Contracts
What is a Master Services Agreement (MSA)?
A type of overarching contract reached between two or more parties where each party agrees to most terms that will govern all other future transactions and agreements.
What kinds of conditions are covered by an MSA?
Payment terms, product warranties, intellectual property ownership, dispute resolution, allocation of risk, and indemnification
Where are MSA (Master Services Agreements) typically used?
Fields that tend to be open-ended and support an organization’s functional areas, like manufacturing, sales, accounting and finance
What is a confidentiality agreement that protects a business’s competitive advantage by protecting its proprietary information and intellectual property?
Non-disclosure Agreement (NDA)
What is a formal document that is routinely employed in the field of project management, which outlines project-specific work to be executed by a service vendor for an organization?
Statement Of Work (SOW)
During a pentest, which document puts into writing the guidelines and constraints regarding the execution of a pentest - most importantly, what is and is not authorized for testing?
Rules of Engagement (RoE)