What defines proper system usage or the rules of behavior for employees when using IT systems?
Acceptable usage policy (AUP)
What does NDA stand for?
What specifies technical and security requirements for planning, establishing, maintaining, and disconnecting a secure connection between two or more entities?
Interconnection Security Agreement (ISA)
What agreement expresses and understanding to work together toward a common goal?
Memorandum of understanding (MOU) or memorandum of agreement (MOA).
What is a BPA?
A written agreement that details the relationship between business partners, including their obligations toward the partnership.
what is a general sanitization term indicating that all sensitive data has been removed from a device?
what is file shredding?
Soem applications remove all remnants of a file, they do so by repeatedly overwriting the space where the file is located with 1s and 0s.
What refers to the process of completely removing all remnants of data on a disk?
Wiping - A disk wiping tool might use a bit-level overwrite process.
What is the special process that removes the random data stored at the end of a file?
Cluster tip wiping
What is an additional step taken after shredding paper to mash or puree the shredded paper?
What is degaussing?
A degauser is a very powerfulu electromagnetic tool. Passing a disk through a degausssing field renders the data on the tape and magnetic disk drives unreadable.
What is the process of physically destroying media to sanitie it?
What is a Data retention policy?
It identifies how long data is retained, and sometimes specifies where it is stored.
Which Act is known as the Financial Services Modernization act that includes a financial privacy rule that requires financial institutions to provide consumers with a privacy notice explaining what information is collected and how it is used?
Gramm-Leach Bliley Act (GLBA)
What Ac trequires that executives within an organization take individual responsibility for the accuracy of financial reports?
Who is responsible for ensuring data is backed up in accordance with the backup policy and is labed correctly for storage?
Who is primarily responsible for ensuring that the organization is complying with relevant laws?
Privacy officer - usually an executive position within an organization
What is an IRP?
Incident response plan
What refers to the order in whcih you should collect evidence?
Order of Volatility
What is the order of volatility?
Data in Cache Memory - including processor cache and hard drive cache
A Paging File on the system disk
Data stored on local disk drives
Logs stored on remote systems
What is a distinct difference between standard system images and forensic images?
Forensic images is an exact copy and does not modify the original. This si not always true with system imaging tools