Rapid Recall Answer Key 24–45
- Confidentiality: internal business need-to-know. Regulation: external law/contract/industry allowed-to-know obligation.
- Need-to-know = internal confidentiality logic; Allowed-to-know = external regulatory/contractual logic.
- Confidentiality aggregates to one highest applicable internal level for the combined data set.
- Regulatory categories are additive: every applicable category/action remains.
- General Audience → Internal Use Only → Confidential → Restricted Confidential → Registered Confidential.
- Examples/obligation families can include privacy/PII, payment/financial, health, contractual/industry, and jurisdiction-specific requirements. Use source examples rather than inventing modern frameworks.
- Excessive privilege: more access than job need. Legitimate abuse: valid access used improperly.
- Privilege elevation: lower rights become higher/admin through exploit/misuse. Excessive privilege: too much was granted initially.
- Service account: non-human process/batch identity for a specific task. Shared account: generic ID used by multiple humans, weakening accountability.
- IDS: detect/notify. IPS: detect and automatically prevent/block/respond.
- SQL injection: unsafe input/query construction lets attacker-supplied text alter database commands.
- Phishing: social-engineering deception/delivery. Malware: malicious software/code; phishing can deliver malware but they are not synonyms.
- Virus: typically host-dependent and spreads through infected file/program execution/sharing. Worm: self-propagates across systems/networks.
- Five activity families: identify requirements; define Data Security Policy; define Standards; assess current risks; implement Controls/Procedures—then manage/monitor/audit/improve.
- Policy: high-level intent. Standard: specific measurable/testable rule for satisfying policy.
- Review/approve: Data Governance Council. Own/maintain: Data Management Executive in the chapter’s model.
- Role Grid: start with data/classification/function and map role access. Role Hierarchy: start with users/workgroups/job families and inherit/restrict privileges.
- Assess what sensitive assets/data exist; what threats/vulnerabilities/exposures exist; what likelihood/impact/control gaps result, considering current controls/evidence.
- CRUD/CRUDE: Create, Read, Update, Delete, and where used Execute permissions between roles/processes and data objects.
- Capture early so classification, access, logging, masking/encryption, architecture, and auditability are designed in, not retrofitted late.
- Accountability/liability for protecting the organization’s data and satisfying obligations remains with the organization even when implementation/operations are outsourced.
- Implementation · Awareness · Data Protection · Security Incident · Confidential Data Proliferation.
← Key 01–23 · Blank-Page Reconstructions →