Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CIPT - Certified Information Privacy Technologist 2022

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
09-10-2022
Written in
2022/2023

Development Lifecycle Release Planning Definition Development Validation Deployment There are four basic types of countermeasures 1. Preventative - These work by keeping something from happening in the first place. Examples of this include: security awareness training, firewall, anti-virus, security guard and IPS. 2. Reactive - Reactive countermeasures come into effect only after an event has already occurred. 3. Detective - Examples of detective counter measures include: system monitoring, IDS, anti-virus, motion detectors and IPS. 4. Administrative - These controls are the process of developing and ensuring compliance with policy and procedures. These use policy to protect an asset. PCI DSS has three main stages of compliance Collecting and Storing - This involves the secure collection and tamper-proof storage of log data so that it is available for analysis. Reporting - This is the ability to prove compliance should an audit arise. The organization should also show evidence that data protection controls are in place. Monitoring and Alerting - This involves implementing systems to enable administrators to monitor access and usage of data. There should also be evidence that log data is being collected and stored. Re-Identification re-identification refers to using data from a single entity holding the data. Symmetric Encryption Symmetric key cryptography refers to using the same key for encrypting as well as decrypting. It is also referred to as shared secret, secret-key or private key. This key is not distributed, rather is kept secret by the sending and receiving parties

Show more Read less
Institution
Course

Content preview

CIPT - Certified Information Privacy
Technologist
Development Lifecycle - Release Planning
Definition
Development
Validation
Deployment

There are four basic types of countermeasures - 1. Preventative - These work by
keeping something from happening in the
first place. Examples of this include: security awareness training, firewall,
anti-virus, security guard and IPS.
2. Reactive - Reactive countermeasures come into effect only after an event
has already occurred.
3. Detective - Examples of detective counter measures include: system
monitoring, IDS, anti-virus, motion detectors and IPS.
4. Administrative - These controls are the process of developing and
ensuring compliance with policy and procedures. These use policy to
protect an asset.

PCI DSS has three main stages of compliance - Collecting and Storing - This involves
the secure collection and tamper-proof storage
of log data so that it is available for analysis.
Reporting - This is the ability to prove compliance should an audit arise. The
organization should also show evidence that data protection controls are in place.
Monitoring and Alerting - This involves implementing systems to enable
administrators to monitor access and usage of data. There should also be evidence that
log data is being collected and stored.

Re-Identification - re-identification refers to using data from a single entity holding the
data.

Symmetric Encryption - Symmetric key cryptography refers to using the same key for
encrypting as well as
decrypting. It is also referred to as shared secret, secret-key or private key. This key is
not distributed, rather is kept secret by the sending and receiving parties

Asymmetric Encryption - Asymmetric cryptography is also referred to as public-key
cryptography. Public key
depends on a key pair for the processes of encryption and decryption. Unlike private
keys, public keys are distributed freely and publicly. Data that has been encrypted with
a
public key can only be decrypted with a private key.

, Choice/Consent - Opt-in = requires affirmative consent of individual
Opt-out = requires implicit consent of individual
Mandatory data collection - necessary to complete the immediate transaction (vs.
optional data collection, which will not prevent the transaction from being completed)
Choice and consent are regulated by CAN-SPAM Act of 2003, European Data Directive
(Articles 7 and 8

De-Identification - Process in which sensitive data is treated in such a way that the
individual cannot be
identified.

EULA - End-user license agreement (AKA software license agreement)
EULA = contract between licensor and purchaser; establishes purchaser's right to use
the software

Cookies - Simple text file that contains name-value pairs. Types of cookies include
persistent
cookies and session cookies. Cookies can be used for:
o Personalization
o Session

OBA/OBM - Online behavioral advertising/online behavioral marketing
Via third-party tracking (e.g. web cookie) to collect and compile user information

LBS - Location-based services
Computer program-level services that include controls for location and time data
E.g. social networking, entertainment, many via mobile devices
Issues: data collection, consent, data sharing

P3P Privacy Policies - P3P = Platform for Privacy Preferences Project, designed by the
World Wide Web
Consortium (aka W3C)

P3P - a protocol that turns a website's text-based privacy policies into a
machinereadable
format

When must a PIA be conducted - Prior to developing or obtaining and IT system or
process which collects,
stores or discloses personally identifiable information

Do Not Track - Do Not Track protection is a feature that is being worked on by the
World Wide Web Consortium tracking protection working group.

Written for

Course

Document information

Uploaded on
October 9, 2022
Number of pages
6
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$11.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
maxiscore Chamberlain College Of Nursing
Follow You need to be logged in order to follow users or courses
Sold
161
Member since
4 year
Number of followers
123
Documents
6957
Last sold
1 day ago
Exam hub

4.0

40 reviews

5
20
4
7
3
8
2
2
1
3

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions