Why classify assets and data?
FIPS
What are the national security classifications of information?
SBU
SSI
CUI
Proprietary
Confidential
Public
Owner of data
Custodians of data
SAM
Hardware Inventory Mangement
What is the first step of Configuration Mangement?
- BC is a security configuration profile
How do you monitor changes in Configuration Management?
- change advisory board that approves the change
What are examples of PII?
PHI
-
What are examples of privacy regulations?
- HIPPA
COPPA
- rules about collecting online data regarding inviduals who are under 13 years of age
PIA
- defines how an organization collects personal data, how it is stored, how it is shared
PTA
- same questions as PIA
GLBA
- Financial information