S1M2 Flashcards
Two types of data breaches
Unintentional
Intentional
Covered members as it relates to HIPPA
Health care provider
Health Plans
Health Care Clearing House
Business associates who need to access records for a covered entity
Three types of safeguards and examples of each
Administrative safeguard - assigning security responsibility, workforce security, security awareness training
Physical safeguards - facility access controls, workstation use and security. device and media control
Technical safeguards - access control, audit control, data integrity control
Who does GDPR apply to
Data processors in the EU
Data processors outside of the EU if they provide goods and services to those in the EU
Data processors outside of the EU but where EU applies via public international law
6 principles of GDPR
Lawfulness
Accuracy
Integrity
Data minimalization
Storage Limitation
Purpose Limitation
6 goals of PCI DSS
Build secure network
Protect Data
Vulnerability management
Implement strong controls
Regularly monitor system
Maintain secure policies