Shared Flashcard Set

Details

CompTIA Sec+ 5.8
Carry out data security and privacy practices
20
Computer Science
Professional
12/01/2018

Additional Computer Science Flashcards

 


 

Cards

Term
Data destruction and media sanitization
Definition
- Burning
- Shredding
- Pulping
- Pulverizing
- Degaussing
- Purging
- Wiping
Term
Burning
Definition
-Documents are incinerated
-Can be combined with other methods
Term
Shredding
Definition
-Documents are cut into small pieces
-long version not secure
-Crosscut more secure but slower
Term
Pulping
Definition
-Paper soaked in a solution until it is reduced to mush
-Can be reused
-Expensive, time consuming, difficult to transport
Term
Pulverizing
Definition
-Can be used for paper or electronic media
-Crushes into small pieces
-Hydraulic or pneumatic machine
-Reduce to loose fibers or shards
Term
Degaussing
Definition
-AC or DC erasing
-Uses Magnetic Field
-Makes Hard drives unusable
Term
Purging
Definition
-Also known as sanitizing
-Removes data remanence
-Data cannot be reconstructed
-Typically considered a step beyond wiping of data
-Used with highly sensitive data
Term
Wiping
Definition
-Over-writes data "x" number of times to ensure it is unrecoverable
-Number of passes can be configured
Term
Data sensitivity labeling and handling
Definition
- Confidential
- Private
- Public
- Proprietary
- PII
- PHI
Term
Data roles
Definition
- Owner
- Steward/custodian
- Privacy officer
Term
Data retention
Definition
-Continued storage of data for compliance or business reasons
-Often policies are created as a collaborative effort of legal, IT, and business owners
Term
Legal and compliance
Definition
-best practices for legal and financial risks
-Keeps organization in accord with regulations
Term
Data Remanence
Definition
the residual representation of digital data that remains even after attempts have been made to remove or erase the data
Term
SSD Disk Sanitization
Definition
-Resets the NAND and marks all blocks as empty
-Each SSD maker has a secure erase tool
Term
DoD 5220.22-M
Definition
Data Wiping method with 3 pass overwrite
Pass 1 Writes Zeroes and verifies
Pass 2 Write Ones and verifies
Pass 3 Writes random character and verifies
Term
RCMP CSEC ITSG-06
Definition
-Data Wiping Method
-Pass 1 writes a one or zero
-Pass 2 Writes the complement of the previous
-Pass 3 Writes a random character and verifies the write
Term
Secure Erase
Definition
Data Wiping
Pass 1: Writes one or zero
-Only for whole disk sanitization, fast
Term
Data Classifications
Definition
-Confidential
-Private
-Public
-Proprietary
-PII Personally Identifiable info (non-PII becomes PII when combined)
-PHI Protected Health Information
Term
Privacy Officer
Definition
A position that oversees all ongoing activities related to the development, implementation, and maintenance of an organizations privacy policies
Term
Examples of Legal and Compliance Regulations
Definition
-Sarbanes Oxley SOX
-Health Insurance Portability and Accountability Act HIPAA
-Gramm-Leach-Bliley Act of 1999 GLBA
(how private information is disclosed from financial institutions)
Supporting users have an ad free experience!