What is Data Protection?
Process of safeguarding important information from harm
What are Data Classifications?
Categories assigned to data based on it’s value to the organization and the damage it could cause to the org if the information were to be disclosed.
What is sensitive data?
Any information that could result in a damages if disclosed
What are 2 classification schemes?
Commercial Business and Government
What are the common levels associated with commercial businesses?
What are the common levels associated with the government?
What is the lifecycle of data?
What is data ownership?
the responsibility and control over data that an organization has, ensuring data quality, security, and compliance.
What are the roles associated with Data Ownership?
Who is the data owner?
Senior exec role that is responsible for maintaining the confidentiality, integrity, availability, and privacy of information
Who is the data controller?
Entity that is responsible for deciding the purposes and methods of data storage, collection, usage, and guaranteeing process legality.
Who are the data processors?
Group or individual hired by the data controller to help with tasks like collecting, storing, or analyzing data.
Who is the data steward?
Focused on data quality and associated data
Who is the data custodian?
Responsible for handling the management of the system on which data assets are stored.
Who is the privacy officer?
Those responsible for the oversight of any kind of privacy related data such as PII. They’re on the hook for data breaches.
Who should the data owner be?
Preferably someone from the business side with each owner being assigned to their own dept.
What are the 3 data states?
What are the different forms of Encryption?
What’s the best tool for protecting data at rest?
Encryption
What are ways of securing data in transit?
What is a SSL?
Secure Socket Layer
An encryption based internet security protocol.
What is a TLS?
Transport Layer Security
An encryption based internet security protocol. Evolved from SSL
What are ways to secure data in use?
What is a regulated data type?
Information controlled by laws, regulation, or industry standards.