Security Fundamentals Flashcards
1
Q
CODE OF ETHICS CANONS
A
- Protect society, the common good, necessary public trust and confidence, and the infrastructure
- Act honorably, honestly, justly, responsibly, and legally
- Provide diligent and competent service to principles
- Advance and protect the profession
2
Q
Confidentiality
A
- Unauthorized access to application, system, or data
3
Q
Integrity
A
- Change or removal of data from a system or product
4
Q
Availability
A
- Disruption or prevention of access to data or services
5
Q
Incorporating Stakeholder Input
A
- Look for subject-matter expertise with internal stakeholders, regardless of roles and responsibility
- Stake holder input is critical in early phases
- Stakeholder buy-in is necessary
- Input from project and program managers is critical
6
Q
Owner
A
- Owns the information
* Determines the classification level
7
Q
Steward
A
- Manages the data and metadata
* Ensures compliance (standards/controls) and data quality
8
Q
Custodian
A
- Is the keeper of the information
* Ensures CIA is maintained
9
Q
Chief privacy officer
A
- Ensures privacy of all data in the entire organization
10
Q
Protecting Privacy: Often mandate from regulations or industry compliance such as HIPAA or PCI-DSS
A
- Data owners
- Data Processors
- Data Remanence
- Collection Limitations
11
Q
Data Loss Prevention (DLP)
A
- Provides strategic methods for ensuring that end users do not transmit sensitive or critical information outside the corporate network
- Stops data breaches and leakage
12
Q
Personally Identifiable information (PII)
A
- Individuals identifiable information
- Consists of first name or initial with last name and one or more pieces of info
- Social Security number, driver’s license number, ID card, financial account number, medical/health info
13
Q
Protected health information (PHI)
A
- Individuals identifiable health information
- Contains at least one piece of info
- Name, address, birth date, phone number, mail or e-mail address, social security number, URL, IP
14
Q
Data Retention
A
- Keeping data until it’s no longer needed
15
Q
Data retention policy
A
- Identifies how, where, and why data will be retained
- Operational use / Current and Future use
- Adherence to legal and regulatory requirements
- Periodic audits