WITH QUESTIONS AND CORRECT VERIFIED ANSWERS
GRADED A+
*data handling* - CORRECT ANSWERS-policies & procedures should be developed for
*handling & disposing of different classifications of data*
data should be *labeled* in order for it to be handled properly
*users should be trained on how to handle data at classifications they will work with*
*role-based training* - CORRECT ANSWERS-more advanced training
- system/network admins
- incident responders
- security management
*data classification & privacy* - CORRECT ANSWERS-*data classification*
evaluating risk level of org's info to ensure that info receives appropriate level of protection
- assign sensitivity, criticality & security priorities
- identify data value
- standardize labeling throughout org
- train employees on classification & protection measures
- audit info classification within org
*high, medium, low, confidential, private, public*
*privacy*
relationship b/w collection & dissemination of data, technology, public expectation of privacy, and legal
& political issues surrounding them
- must classify to apply privacy
- PII