CISSP考试指南笔记:2.8 快速提示

  • Information goes through a life cycle that starts with its acquisition and ends with its disposal.
  • Each phase of the information life cycle requires different considerations when assessing risks and selecting controls.
  • New information is prepared for use by adding metadata, including classification labels.
  • Ensuring the consistency of data must be a deliberate process in organizations that use data replication.
  • Data aggregation may lead to an increase in classification levels.
  • Cryptography can be an effective control at all phases of the information life cycle.
  • The data retention policy drives the timeframe at which information transitions from the archival phase to the disposal phase of its life cycle.
  • Information classification corresponds to the information’s value to the organization.
  • Each classification should have separate handling requirements and procedures pertaining to how that data is accessed, used, and destroyed.
  • Senior executives are ultimately responsible to the shareholders for the successes and failures of their corporations, including security issues.
  • The data owner is the manager in charge of a specific business unit and is ultimately responsible for the protection and use of a specific subset of information.
  • Data owners specify the classification of data, and data custodians implement and maintain controls to enforce the set classification levels.
  • The data retention policy must consider legal, regulatory, and operational requirements.
  • The data retention policy should address what data is to be retained, where, how, and for how long.

剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:2.8 快速提示

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值