Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

C838 Exam 4 Questions with 100% Correct Answers.

Document preview thumbnail
Preview 2 out of 6 pages

C838 Exam 4 Questions with 100% Correct Answers.

Content preview

C838 Exam 4 Questions with 100%
Correct Answers.
Organization risk knowledge items

An inventory of all assets
A valuation of each asset
A determination of critical paths, processes, and assets
A clear understanding of risk appetite

Secondary input etitities for P&PD

Data location allowed
Data breach constraints
Data retention constraints
Categories of users allowed
Security measures to be ensured
Status

Categories of personal data that can be processed

Sensitive data
Telephone or Internet data
Biometric data
Personal data
Categories of the processing to be performed

Data Discovery Issues

Hidden costs
Dashboard
Poor data quality

Data Retention Policy requirements

, Retention periods
Data formats
Data security
Data retrieval procedures for the enterprise

Features of IRM

Sets up a baseline for the default Information Protection Policy
Adds an extra layer of access controls on top of the data object or
document Protects sensitive organization content
Contains ACLs and is embedded into the original file, therefore IRM is agnostic to the
location of the data

Approches to data masking

Random substitution: Replaces the value with a random value
Algorithm substitution: Replaces the value with an algorithm-generated value
Shuffle: Shuffles different values from the data set
Masking: Hides certain parts of the data using specific characters
Deletion: Deletes the data or uses a null value

Challenges with Key Management

Backup and replication: The nature of the cloud can affect the ability for long- and short-term
key management.
Access to the keys: Permitting permission for accessing keys by CSP employees or personnel is
an important criteria.
Key storage: Secure keys' storage is essential for the security of data.

ISO/IEC 27043:2015

Information technology — Security techniques — Incident investigation principles and processes

ISO/IEC 27018:2014

Information technology — Security techniques — Code of practice for protection of personally
identifiable information (PII) in public clouds acting as PII processors

Document information

Uploaded on
May 9, 2025
Number of pages
6
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
QUINTER
3.6
(72)
Sold
406
Followers
106
Items
39872
Last sold
13 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions