Data Management Flashcards

(24 cards)

1
Q

What are different types of data security tech?

What are good disaster recovery procedures?

A
  • Disk encryption (secure hard drive)
  • Cloud Storage (digital data on remote servers / internet)
  • Password protection & anti-virus software protection
  • Firewall & disaster recovery procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why do you mean by copyright?

A
  • Set up exclusive rights granted to an author or creator of any original work.
    o These rights can be licensed, assigned or transferred
    o Form of intellectual property
    o Crown Copyright: all material created and prepared by the Government, e.g. laws, public records, OS mapping.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What regulation governs data management in the UK?

A

Data Protection Act, 2018 and within that:

UK General Data Protection Regulation (UK GDPR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the UK data protection act 2018 set out?

A
  • Set out rules and principles as to how companies process personal data
  • The act includes UK GDPR
  • the key principles of UK GDPR
  • Define individual rights regarding their information
  • Require data to be handled lawfully fairly and securely.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can you tell me about UK GDPR?

A

Aim: Create a single data protection regime affecting businesses and empower individuals to take control of how their data is used by 3rd parties.

Gives people right to be informed about how 3rd parties use their info.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who polices a data breach?

A

Information commissioner’s office (ICO).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What you call the person in your company who ensures data protection laws?

A

Data Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what is the penalty for a data breach?

A

Fines up to 4% of global turnover of the company or £17.5 million (whichever is greater).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If there is a data breach within your company what do you do?

A
  • Inform your Data Controller
  • Report it to a client
  • Report it to your company
  • report it to the Policed by information commissioner’s office (ICO) within 72 hours
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What were the key principles set out in Article 5(1) of UK GDPR?

Or: What are some principles of the Data Protection Act?

A

1) D - Data minimisations
2) I - Integrity and confidentiality
3) L- Lawfulness, fairness and transparency
4) A - Accuracy
5) A - Accountability
6) P - Purpose limitation
7) S - Storage limitations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who are the key persons within UK GDPR?

A

Data Controller: Reporting breaches / leaks
Data Processer: Examine data
Data Protection officer: Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does data accountability mean?

A

Ensures organisations can prove to the ICO how they comply with regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the Freedom of Information Act say?

A

Right for individuals to access info held by public bodies unless contrary to GDPR/ criminal investigation.
* Public body:
o Inform individuals requesting sight of info whether it holds it.
o Must supply it in 20 working days (in same format) – can charge for info.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can you ensure employees competence to addressing phishing?

A

Ensuring there is adequate training is put in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is JLLs data retention policy?

A

Only hold as long as required for legitimate business purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How many individual rights are there within UKGDPR? and what are they?

A

8 individual rights:
* Right to be Informed
* Right of Access
* Right to data Portability (to use for their own purposes)
* Right to Object
* Right of Rectification
* Right to Restrict processing
* Right to Erasure
* Right to automated decision making and Profiling (undertaken by insurance companies

17
Q

What is a Non-Disclosure Agreement?

A
  • Legally enforced contract between two parties relating to sensitive information
  • Agreement will create a confidential relationship between a person who has sensitive info and a person who has access to that info.
  • Party harmed by breach of NDA can take legal action (seek damages for any losses that were incurred).
18
Q

What can you tell me about the Use of Artificial Intelligence.

A
  • RICS have completed public consultation on: Professional Standard: Responsible use of AI 2025 (1st Edition)
  • Provides guidance on the ethical and practical considerations of AI and the natural and built environment
19
Q

What is a firewall

A

a network security system that acts as a barrier between a trusted internal network and an untrusted external network

20
Q

What is Triangulation

A

using multiple data sources to verify the data / info

21
Q

What is your companies firewall?

A

Palo Alto Networks, Inc.

22
Q

What is cloud computing?

A

A cloud computing model that enables storing data and files on the internet through a cloud computing provider that you access either through internet/private connection

23
Q

What are key requirements under the Data Protection Act, 2018

A
  • Obligation to conduct data protection impact assessments for high risk holding of data
  • New rights for individuals to have access to information on what personal data is held & to have it erased
  • Data controller decides how and why personal data is processed and is directly responsible for GDPR
  • Principle of ‘data accountability’ ensuring organisations can prove how they comply with regulations can prove the information commissioners officer (ICO)
24
Q

Who is responsible for GDPR within your company?

A

Data Controller