Data classification, ownership, and asset handling requirements tested on CISSP Domain 2.
36 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary goal of information classification in asset security?
- To assign sensitivity levels to data that determine how it must be protected, stored, and handled based on its value and risk.
- Name four common data classification levels used in organizations.
- Public, Internal, Confidential, and Restricted (or Secret). Specific names vary by organization.
- What does the data owner role involve?
- Setting classification levels, defining access permissions, approving data use, and ensuring compliance with policies.
- What is the primary responsibility of a data custodian?
- Implementing the data owner's protection requirements, managing day-to-day storage, backup, and access control enforcement.
- Define personally identifiable information (PII).
- Information that can be used to identify an individual, such as name, Social Security number, date of birth, email, or financial account details.
- What is protected health information (PHI)?
- Health data that can identify an individual, regulated under HIPAA, including medical records, treatment history, and insurance claims.
- What does data stewardship require?
- Accountability for data quality, proper handling, and compliance with regulations and organizational policies throughout the data lifecycle.
- What is a data controller under GDPR?
- The entity that determines the purposes and means of processing personal data.
- What is a data processor under GDPR?
- An entity that processes personal data on behalf of and under instruction from a data controller.
- What is the purpose of a data retention policy?
- To specify how long each type of data must be kept before approved deletion, balancing legal/operational needs with privacy.
- What is data minimization?
- A privacy principle requiring collection and retention of only the minimum personal data necessary for a stated purpose.
- What does purpose limitation mean?
- Personal data collected for one purpose cannot be used for an unrelated purpose without additional consent or legal authority.
- What is an asset inventory in information security?
- A documented record of all organizational data assets, their classification, location, owner, and protection requirements.
- What is data labeling?
- Marking assets with visible or embedded classification levels so handling requirements are clear to anyone who accesses the data.
- What encryption level is typically required for confidential or restricted data?
- Strong encryption (AES-256 or equivalent) both in transit and at rest.