Understand Platform Concepts Flashcards
Classification
Determine what data.
Determine whose data
Find sensitive ‘non personal’ data that matches a pattern, often using regular expressions
Classification Advantages
can be pre-packaged, works without an
entity context.
Classification Considerations
regexs are usually complex, apply only
for specific patterns, and language-specific (if based on words)
Correlation
Determine whose data
Connect entities with their personal data, using
smart discovery and correlation
Correlation Advantages
directly correlates data to its owner, complies with modern privacy regulations
Correlation Considerations
requires providing the list of entities as a starting point, requires a robust correlation
algorithm.
BigID fully supports Classification and Correlation - centering around privacy and connecting personal data with its owners to
comply with modern regulations, while also covering the traditional need to find systems containing sensitive data types
Entity Sources
Identifying attributes that describe who you are (preferably permanently and uniquely)
Data Sources
Data that can be linked to you, and potentially
associated with those identifying attributes
Entity sources are only needed for correlation. They are not needed for
classification and clustering.
BigID Terms – Categories
- Also known as “Business Glossary”, used to associate entity attributes with business categories
- Defined in Administration → General Settings → Business Glossary
BigID Terms – Tags
- Also known as “Saved Queries”, used to speed up data querying
- Defined in Administration → Tags - Saved Queries
BigID Terms – Labels
• A label like “Confidential” and “Sensitive” that can be attached to a tag and propagated to Azure
Information Protection
• Defined in Quick Apps → Azure Information Protection
BigID Terms – Lawfulness of Processing
• Lawfulness of Processing - legal circumstances that allow saving a personal data attribute, such as compliance with legal obligation, public interest, or consent
BigID Terms – Purpose of Use
• Purpose of Use - the purpose for which a personal data attribute is used, as stated by the enterprise