C838 Exam 5 Questions with 100%
Correct Answers.
Data subject
the individual whom the PII refers to. Aspecific human being.
Data controller
any entity collecting or creating PII. in the cloud motif, this is the cloud customer.
Data processor
Any entity acting on behalf or at the behest of the data controller, performing any
manipulation, storage, or transmission of the PII. Known as the Cloud service provider.
Australian privacy act of 1988
regulates the handling of personal information. It includes details regarding the collection, use,
storage disclosure, access to, and correction of personal information. Covers issues as -
Transparency
-rules on collecting information from solicitation.
-correctness and integrity of data.
ISO/IEC 27017
The international organization for standardization and international Electrotechnical
Commission, a set of standards regarding the guidelines for information security controls
applicable to provision and use of cloud services and cloud services customers. How cloud
customer info and privacy should be controlled.
Personals information Protection and Electronic Documents act (PIPEDA)
conforms to the EU data directive and privacy regulation. Provides guidelines which describe
how businesses should manage the personal data in a commercial activity.
ISO/IEC 27037
Guide for collecting, identifying, and preserving electronic evidence.
, ISO/IEC 27041
Guide for incident investigations
ISO/IEC 27042
Guide for digital evidence analysis
ISO/IEC27043
Incident investigation principles and processes
ISO/IEC 27050
Overview and principles for eDiscovery
eDiscovery
Refers to the process of identifying and obtaining electronic evidence for either prosecutorial
or litigation purposes. Used for several types of services such as SaaS-based and hosted based.
Chain of Custody
Creates documentation about who had access to evidence and what modifications were
performed on it. Tracks and monitors all the evidence from the time it is recognized as evidence
and acquired for a purpose.
SOC- 1
It is an audit engagement consisting solely of an examination of organizational financial
reports controls. for cloud customers this is useless. designed around a specific point in time.
SOC 2
Reports review controls relevant to security, availability, processing integrity, confidentiality, or
privacy. Report of most use to cloud customers(to determine the suitability of cloud providers)
and IT security practitioners.
SOC seven categories
-Organization and management
-communication
Correct Answers.
Data subject
the individual whom the PII refers to. Aspecific human being.
Data controller
any entity collecting or creating PII. in the cloud motif, this is the cloud customer.
Data processor
Any entity acting on behalf or at the behest of the data controller, performing any
manipulation, storage, or transmission of the PII. Known as the Cloud service provider.
Australian privacy act of 1988
regulates the handling of personal information. It includes details regarding the collection, use,
storage disclosure, access to, and correction of personal information. Covers issues as -
Transparency
-rules on collecting information from solicitation.
-correctness and integrity of data.
ISO/IEC 27017
The international organization for standardization and international Electrotechnical
Commission, a set of standards regarding the guidelines for information security controls
applicable to provision and use of cloud services and cloud services customers. How cloud
customer info and privacy should be controlled.
Personals information Protection and Electronic Documents act (PIPEDA)
conforms to the EU data directive and privacy regulation. Provides guidelines which describe
how businesses should manage the personal data in a commercial activity.
ISO/IEC 27037
Guide for collecting, identifying, and preserving electronic evidence.
, ISO/IEC 27041
Guide for incident investigations
ISO/IEC 27042
Guide for digital evidence analysis
ISO/IEC27043
Incident investigation principles and processes
ISO/IEC 27050
Overview and principles for eDiscovery
eDiscovery
Refers to the process of identifying and obtaining electronic evidence for either prosecutorial
or litigation purposes. Used for several types of services such as SaaS-based and hosted based.
Chain of Custody
Creates documentation about who had access to evidence and what modifications were
performed on it. Tracks and monitors all the evidence from the time it is recognized as evidence
and acquired for a purpose.
SOC- 1
It is an audit engagement consisting solely of an examination of organizational financial
reports controls. for cloud customers this is useless. designed around a specific point in time.
SOC 2
Reports review controls relevant to security, availability, processing integrity, confidentiality, or
privacy. Report of most use to cloud customers(to determine the suitability of cloud providers)
and IT security practitioners.
SOC seven categories
-Organization and management
-communication