Skip to content

Rapid Recall Answer Key 24–45

  1. Confidentiality: internal business need-to-know. Regulation: external law/contract/industry allowed-to-know obligation.
  2. Need-to-know = internal confidentiality logic; Allowed-to-know = external regulatory/contractual logic.
  3. Confidentiality aggregates to one highest applicable internal level for the combined data set.
  4. Regulatory categories are additive: every applicable category/action remains.
  5. General Audience → Internal Use Only → Confidential → Restricted Confidential → Registered Confidential.
  6. Examples/obligation families can include privacy/PII, payment/financial, health, contractual/industry, and jurisdiction-specific requirements. Use source examples rather than inventing modern frameworks.
  7. Excessive privilege: more access than job need. Legitimate abuse: valid access used improperly.
  8. Privilege elevation: lower rights become higher/admin through exploit/misuse. Excessive privilege: too much was granted initially.
  9. Service account: non-human process/batch identity for a specific task. Shared account: generic ID used by multiple humans, weakening accountability.
  10. IDS: detect/notify. IPS: detect and automatically prevent/block/respond.
  11. SQL injection: unsafe input/query construction lets attacker-supplied text alter database commands.
  12. Phishing: social-engineering deception/delivery. Malware: malicious software/code; phishing can deliver malware but they are not synonyms.
  13. Virus: typically host-dependent and spreads through infected file/program execution/sharing. Worm: self-propagates across systems/networks.
  14. Five activity families: identify requirements; define Data Security Policy; define Standards; assess current risks; implement Controls/Procedures—then manage/monitor/audit/improve.
  15. Policy: high-level intent. Standard: specific measurable/testable rule for satisfying policy.
  16. Review/approve: Data Governance Council. Own/maintain: Data Management Executive in the chapter’s model.
  17. Role Grid: start with data/classification/function and map role access. Role Hierarchy: start with users/workgroups/job families and inherit/restrict privileges.
  18. Assess what sensitive assets/data exist; what threats/vulnerabilities/exposures exist; what likelihood/impact/control gaps result, considering current controls/evidence.
  19. CRUD/CRUDE: Create, Read, Update, Delete, and where used Execute permissions between roles/processes and data objects.
  20. Capture early so classification, access, logging, masking/encryption, architecture, and auditability are designed in, not retrofitted late.
  21. Accountability/liability for protecting the organization’s data and satisfying obligations remains with the organization even when implementation/operations are outsourced.
  22. Implementation · Awareness · Data Protection · Security Incident · Confidential Data Proliferation.

← Key 01–23 · Blank-Page Reconstructions →