2 cissp ® Official Study Guide Eighth Edition


Understand the importance of data and asset classifications



Download 19,3 Mb.
Pdf ko'rish
bet189/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   185   186   187   188   189   190   191   192   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Understand the importance of data and asset classifications. 
Data owners are responsible 
for defining data and asset classifications and ensuring that data and systems are properly 
marked. Additionally, data owners define requirements to protect data at different classifica-
tions, such as encrypting sensitive data at rest and in transit. Data classifications are typically 
defined within security policies or data policies.


Written Lab 
189
Know about PII and PHI. 
Personally identifiable information (PII) is any information that can 
identify an individual. Protected health information (PHI) is any health-related information that 
can be related to a specific person. Many laws and regulations mandate the protection of PII 
and PHI.
Know how to manage sensitive information. 
Sensitive information is any type of classi-
fied information, and proper management helps prevent unauthorized disclosure resulting 
in a loss of confidentiality. Proper management includes marking, handling, storing, and 
destroying sensitive information. The two areas where organizations often miss the mark are 
adequately protecting backup media holding sensitive information and sanitizing media or 
equipment when it is at the end of its lifecycle.
Understand record retention. 
Record retention policies ensure that data is kept in a usable 
state while it is needed and destroyed when it is no longer needed. Many laws and regula-
tions mandate keeping data for a specific amount of time, but in the absence of formal 
regulations, organizations specify the retention period within a policy. Audit trail data needs 
to be kept long enough to reconstruct past incidents, but the organization must identify how 
far back they want to investigate. A current trend with many organizations is to reduce legal 
liabilities by implementing short retention policies with email.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   185   186   187   188   189   190   191   192   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish