Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.

In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:

· CISSP / Cybersecurity Integration – Data Remanence - Rainbow Series

· CISSP Training – Protecting Privacy

· CISSP Exam Question – Sensitive Data / Destroying Hard Drive

BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com

Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?

LinkedIn – www.linkedin.com/in/shongerber

CISSPCyberTraining.com - https://www.cisspcybertraining.com/

Facebook - https://www.facebook.com/CyberRiskReduced/\

LINKS:

  • ISC2 Training Study Guide
  • https://www.isc2.org/Training/Self-Study-Resources

  • Quizlet

  • https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/

  • Misc.:

  • https://thorteaches.com/cissp-certification-rules-laws-and-regulations-oecd/

  • OECD

  • http://www.oecd.org/sti/ieconomy/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm

  • Rainbow Books

  • https://fas.org/irp/nsa/rainbow/tg025-2.htm

  • GXA

  • https://gxait.com/network-security/data-remanence-putting-business-risk/

Transcript:

…Hey all is Shon Gerber again with reduced cyber risk And I hope you're all having a wonderful morning. I'm having a great morning My kids are heading off to, to camp this today So I am extremely excited about that They have, I have five children still at home and they are all going to camp. and it is an exciting exciting time. I don't know if any of you all have children might be living out there, but anytime that you can get away from the kids or the kids can get away from you. It's a wonderful blessing And you think those your lucky stars for having those little blessings Because, yeah it's going to be a super quiet in the house and I'm pretty excited about that because it'll just be my wife and me and the dogs It'll be pretty awesome. so yeah, that's just had to give that a little bit of a tidbit out there about that. So one of the things that we're going to be talking about today a lot of great cybersecurity aspects that are going to be dealing with training. And we're going to have a talk about cybersecurity Integration is going to be the data remnants and rainbow series. We're going to be talking about data remnants as the CIS S P training and what you need to understand. for the CISSP exam. And then we're gonna talk about some CIS S P exam questions that are around sensitive data and destroying of hard drives. But before we do one of the things I want to mention is the C I S S P training courses that are available. to you just for individuals who listen to this podcast. You will find out that there are some great training courses that I have available on youtube.com. that are around the CISSP. And they actually focus on all eight domains of the CISSP. So the training you see here you're going to get that in on the steroids They're going to be tons of it. and we'll go through each and every domain as it relates to the CIS SP from domain one to domain eight And you can get all of those as you well know. To me they're bargain basement prices That are pretty amazing. the the cool part about that is that by going to the link of reduced cyber risk.com. dash training. You can get those that link all in one spot from basically domain one to domain eight. And that will take you to. you to me.com. Where you can then purchase those, those courses But again you get lifetime access. It's an incredible opportunity If you just want to go to you to me or to go to reduce Avaris. Dot com CISSP training. those are some great opportunities for you there. All right. Well lets us roll on into the training today. Okay So let's CIS S P cybersecurity integration training We are going to talk about the NSA slash N C S C S Brainbow series And you've heard me talk about this especially as you're dealing with the CISSP. There's different rainbow series books that you will deal with. and one of the main questions they talk about in there is what what is it a specific book and why does it do what it does? what what is the aspect of it? And we're going to kind of go into a couple of that right today But the interesting part was I had gone through and been teaching the CIS as P for awhile and, and understood the rainbow series And I remember being in cybersecurity now for as many years as I have basically since 2001. you you realized that the, the rainbow series are an important aspect. Of the overall picture that you know especially at the beginning how this whole thing worked, but I never really understood where they were and and you can get these all online in the past They were in actual books that you would get because that's how old I am You would actually have a book not online. But now they're all online that you can go check them out on at, at at the NSA. and that's basically F fast.org, IRP NSA rainbow and so on and so forth And they will walk you through You'd see where all the books are at. But there's some key terms we're going to focus on today And this is around, dealing with. Data remnants And that's the whole aspect of it I kind of wanted to keep all of these domains as we talk about cybersecurity and the integration and the different, websites that are out there for cyber security. I want to focus on the specific domain that we're in and we're dealing with it Cause it, I was kind of jumping around a little bit I thought well let's just keep it focused on what individual domain we're dealing with so that it makes it a bit easier as your say. this information. So the key terms we need to be aware of is one first one is clearing and this is what they call it removing the sensitive data from an information system So if you have some sort of data that's out there and you want to remove it this is how you clear the data from that device. and there's some different terms that you will get to know quite frequently. another one is purging and this is actually removal of the sensitive data from a period of processing So what they talk about there is it actually removes it from the processing. period that's occurring on that device that hard drive that disc, that the information is being stored on a declassification is removal of security classifications of a subject media. Now in the previous life where I dealt with the military we had unclassified. You have your classified networks you're on classified networks You, when you had classifications your secret top secret and so forth, you had to remove that security classification. If you want to be able to use that data in spaces that are outside of what they were designed for. A good example of that is like in the case of the Mueller report in the United States they had, those are classified documents in some respects. Because maybe they give out information about, individuals in this report So what happens is is it has to go through a process of declassification before they can do that. And and so. Like for example if I get a document. And you know I'm, I'm the author of even can come down from a declassification standpoint. If I'm the author of a document I can classify that document So I can say it's classified secret. then what ends up happening though is I cannot be the one that says I'm going to declassify and I'm just going to remove this the security clearance off of that. Cause it was a reason I made it. At classification of secrets So therefore it has to go to an individual who then has to review and say, okay yeah if you remove this information it is would be unclassified or parts of it would be redacted. And so therefore that's what the declassification process is It's a it's a whole process a whole way of removing that information. coercive…okay See I can't even say that course activity My third grade educations coming out. yeah, that that word. It's measured in This is another word that I can't handle. Oh or stats or steads and it's basically don't oh E and this is a property of magnetic material used as a measure of the magnetic field. Okay So if you're geeking out that's what that is It's a V they call that oh eight Now I'm I'm geeking on you a little bit here. just because one as I'm teaching this I also have learned it. I did not really know and understand how that was all set out So it's like oh okay Well then now that makes more sense versus just going. Yeah you need to purge it You need to remove it. So this is a little level deep detail that you may be going, why are we getting into this Well it's just to kind of show you a little bit more around It's not just, Hey I'm going to clear it I'm going to purge it and I'm going to declassify it because those are key terms You'll need to know for your CISSP. But when it comes right down to it there is a little bit more backstory behind it…Now I knew I do know that that we talk about in the CIC. the different types of tapes and there's a type one type two type three tape, and these are magnetic tapes And these have a coercive the civic duty of the mat type one is three 50 O E. The type two is 3 51 0 8 to 7 51. And the type three is above 75 or 750. I said 3 51 Yeah 750. So basically it was 3 50, 3 50, 1 to seven 50 and seven 50 and above. And those are the different types of tapes that are available magnetic tapes And again this is like way old. If you're talking people like me but, in many cases he data centers still have magnetic tapes that. I information is backed up too. So you need to keep that in mind especially as it deals with destruction how do you deal with that And it also comes down to the the tape that. the magnet magnet Tivity of a hard disc drive. Now what does it…well that is a device that generates a magnetic field for deep browsing magnetic storage. My media, what does that mean? It basically puts this quote-unquote force field and it you put your magnetic tape in there and it's got these humongous monsters magnets. That then just basically rearrange all the bits and they no longer are in a logical path that, that allows the device to be able to point to them. Cause they all have pointers And if you have a certain file it points to a certain place on the hard disk drive If you're dealing with just drive. And the D Geyser. We'll nuke that it will totally mess up those hard disc drives Now, as we have SSDs come into play the D Gaza really has no factor in any of that So then you'll have to get into physical destruction. but bottom line is that's where you're still a lot of magnetic tapes that are out there. That you need to be concerned with and worried about. And so therefore that's just something to consider. permanent magnetic decomposer. this is a handheld permanent magnet that can be used to dig cows floppies Yes they are floppies and they still exist. And be you'd be surprised There's still people using floppies. I don't know how you can use them that much but there are probably plenty of out there that still use a floppy drive. And if you're not familiar with that is it's like a little square. Plat piece of plastic it used to be plastic It was just kind of the magnet. Magnet. It was the. The spinning magnetic drive per se on. Pacey flimsy piece of…plastic that would hold the data and it would just go…That's kind of how that worked and it made those specific noises too Pretty scary. but that that was the old way they used to deal with floppy drives and they also can deal with it on Desplat. Which is basically your hard drives and magnetic drums et cetera So it was basically a handheld decals or that you could go by and walk by and you nuke a hard drive. now there wasn't used obviously to do gals tape the best thing to do with tape. Honestly it's shredded Just destroy it. it makes it a whole lot easier that way. But the permanent decals or wood is just a high powered magnet You can be Magneto from the X-Men and just nuke. Your stuff. Bottom line though is on. Don't get close to anything You don't want a new cause if you do it's done You're not going to use it again. So that is a permanent magnet decomposer. So now if you're looking at different mid risk considerations for storage and media reuse these are some key aspects for you to keep in mind. the you need to understand the destination of the released media. And where you plan on keeping it So if you plan on storing it. What are you going to do once you release it Where's it going to be stored And it's going to be stored in a salt Mine is going to be stored in a warehouse. where where's it going to be stored Because all of those things will affect how well the data is kept. for an example if you're dealing with. heat and age you know, those all of that will age the device if you keep it for a long period of time that will cause issues with the data. So all of those things will cause you some level of grief if, as it relates to your maintaining your information. mechanical storage of device equipment failure If you have, as you keep these things online. What'll happen is the mechanical devices will be we'll have issues. they will have problems and they won't be able to last a long period of time So your storage and where you keep it. We'll also cause issues with mechanical failure and bottom line is if you have these old devices, they also don't, they you can't get replace them So you may have the hard drive but if you don't have the chassis and. All of the operating systems that go along with to run these old systems. That also is a factor you need to be aware of. there's also a comment that your storage device segments not receptive to overwrite And we'll talk about that here a little bit further about not receptive to overwrite What does that mean? but they basically won't You do you can't it won't override it at all It says Nope, I'm done You can't mess with me anymore And you can't make changes to it. overwrite the software and clearing and purging So again you got to have find a specific overwrite software that will do this clearing and purging for you. those are some things to keep in mind As you, as these things get older, you got to have the older software to do it New software will not work with, these old systems So you'll have to keep that So there's a lot of legacy stuff You've got to keep in mind by keeping these older data. the asshole as time goes on you may not understand the data sensitivity of it It sits in this big box for years. Is it sensitive Is it pictures of my fuzzy kitty? Or is it pictures of top secret nuclear science projects which you hopefully wouldn't keep in a box somewhere but you never know people do those things. so again not understanding that to hold dense data sensitivities especially if you're keeping it for a long period of time. And then improper use of degaussing equipment. I struggled with this one but knowing myself when I was a teenager I'm trying to think what would be one thing that I would be using improper housing equipment and probably I guess, Hey let's run through the magnetic field and see what it does. I mean, I guess that's what, but basically going and playing with your friends going Hey I'm Magneto watch out for me You know, those things. I just struggle with why you would use it improperly because you're playing with big monster magnets and they're kind of in the past they've been pretty good size. And but now they're in a box more or less that you just stick the device in a box and it nukes it. But yeah I laughed at that one improper use of decals of equipment So do not know horseplay with the housing equipment. That just goes bad. It goes bad for everybody…Now when you're dealing with not receptive to overwrite some the storage devices segments are not receptive to this And what happens is is that they're unusable tracks on a disc drive. And I come back to disc drives again because you know we all know that they're going to SSDs are more prevalent within our environment, but there's still a lot of disk drives that are out there that are being used in servers. When you can't overwrite the segments it becomes very difficult to wipe. and so therefore if it becomes difficult to wipe, how are you going to deal with that? so you need to check these devices for unusable or damaged areas before uploading the data and making sure like one good thing we've talked about on reduced cyber risk. Was the Amazon glacier and how you could potentially put all of this data in the cloud. But if you run into these issues of overwrite challenge. one you go okay well I'm going to do that I'm going to upload it to the cloud Well I find out I have these unusable or damaged areas. How you going to deal with that And I will put a little plug out there for spin right by Steve Gibson It's a really good product to help damaged areas within your device drives. I highly recommend that if you're going to be used if you need to get the data off of there. but also keep in mind from a cybersecurity standpoint if you can't get the data off of this, and if it's sensitive you need to really make sure the best thing to do is. I mean the housing is important I think it's it's good. And personally I think it's probably step one of a two-step process especially if you're dealing with sensitive data, is that you dig out the Dickens out of it and then you shred it. or you know what just shred it and be done with it And you don't have to worry about the housing It. But the bottom line is is that if you have any areas that are. Damaged. and they do not give that DCD aware that disc drive away because what'll happen is if you do that you are now running the risk that someone could get access to that data. you never know if the technology's out there They may be able to get access to this damaged or unused spot. if it is unreceptive again, Tried to gouging re-imaging the device or re-imaging it? if you did gals that you, you knew it you can't really use it anymore but those are things you need to consider. If you the segments do not have the ability to overwrite. Okay That's all I have for the cybersecurity integration Let's roll on to the CISSP SSP training. Okay This is domain two asset security and more topic is going to be about protecting privacy Two dot three. Okay As well the objective is two dot three a protecting your privacy and the topic on this is data processor. so we're going to get into a lot of these different aspects and a lot of this falls into what GDPR talks about, and if you're not sure what GDPR is the general data privacy regulation that's put out by the European union. As it relates to data privacy and maintaining it And that is, it's a pretty large. Regulation that focuses on, managing. the data privacy of individuals in the European union. the big thing that made this thing happen to come into play there was safe Harbor in place before this. but what moved it in this direction was the fact that they wanted to have better access and better control of data privacy. Now it's interesting because you look at data privacy from the EU is one direction which is more or less focused around the individual. And how do we protect the rights of the individual that European union citizen? And then you go to the opposite extreme where you have the Chinese government where it is the privacy of the state. Now the privacy of the people is important to the Chinese government obviously, but it's more important to the privacy or the understanding of the state and the collective. And then you have United States was really kind of in the middle It's kind of all over the place. So you get different states in the United States that are more private than others And so that adds com. Convoluted T convolute com. Yeah it makes it all messed up. Get you that third grade education. but you. it ends up messing things up because you have different states that have different requirements. So bottom line is is where this part is going to be around GDPR. Now context is everything as it relates to processing data, a system to process data or is it looking at the GD PR data processor? Processor is defined as this, a legal or a natural or legal person, public authority agency or other body, which processes personal data. Solely only behalf of another data controller. So what it really basically comes down to is you have an individual who's a data controller that controls the information that from within an organization. You can outsource this the to a third party which would be a data processor. one thing that you can see as this as an. always works is so you have a. A third party. Processes that does payroll that would have personal information about the individual, from pay name address all those things that you considered as. personal information, you actually that you consider just an IP address of the computer you're using as personal information. So they would have all of this data. So this, this data processor can be defined as an individual person. that within your organization who has the authority to do this or it can be outsourced to a third party. And so therefore you need to be aware of how does that affect your company How does that affect. what you're doing and then how do you want to make sure that you document that correctly, but a data processor. Happens quite frequently. you just have to decide is it somebody internally Is it externally or is it a combination of both…Now we talked about GDPR One of the big aspects of them making this thing have some teeth is the fact that it is a fight You could face fines up to 4% of global revenue. Now 4% is a lot of money especially with you're dealing with a corporation. who has a global presence? you know and even if you're small company so. it to this way So if you're making. A hundred thousand dollars a year right? So a hundred while hopefully you're making more than that but let's say it's a million dollars a year. So if you have a million dollars a year, 4% of a million dollars is a what is that I don't really, I say I had to do math in public I have to think about that for I did it So maybe what $4,000 No it'd be. 1%. 1% of a million dollars. Okay 10% is a hundred thousand dollars. of a million, so yeah 10% was a 4% would be a $40,000 right Yeah $40,000. So it's $40,000 hit. And that's if you're doing a million dollars in business now that, that a million dollars of business. You get a $40,000 hit your margins Aren't very high. That could be DECA. So let's put it this way So many businesses are only making if I say. Many. The average comes into. If you're a good business making big money. and you're you're blessed. You're probably making about 8% margins on your product. So you know anywhere from six 8% is what the typically what I've seen again I'm not a finance guy I'm a cyber guy So what the heck do I know? But I do know that typical margins from a business, some businesses have way higher margins than that but let's just say it's a standard businesses making between six and 8% of their margin. Well if you take an 8% of your margin if you're lucky to get that, then you could face fines a 4% So you could also take a 4% hit of your overall profit. That is huge hat 50% could be put in paying out these fines. so it seems like not very much but when your margins are pretty tight it's a lot of money. so an example I have is if you got a billion dollars USD globally, that's a $40 million fine. That is huge. That is a monstrous fine That would cost you gobs and gobs of money. Now as you're dealing with the EU and us privacy shield this will again was previously safe Harbor. there's organizations can self-certify saying that they meet or comply with the privacy shield requirements and principles. so therefore yeah. can in the past you could do that You'd say Hey I'm doing it I'm saying I'm doing it. If you want to audit me audit me and then you can find out if I'm actually saying doing what I'm saying. and but that's that was the U S us privacy shield our EU us privacy shield. There were 16 principles in total that you need to vow to uphold at least seven of them. And so therefore you could actually get away with not upholding them all. but those are the aspects that you had to say that I will comply with that And then therefore they had the right to audit you And if they audited you and you weren't doing at least the seven. Well then you would have to pay some significant fines for doing so could lose that status, all of those pieces And then if you lose status what that ends up happening is is now you can no longer share data between you and the EU. so if you're in the United States and you're a multinational, you've got business in the Europe and in the United States, you can no longer share data between you and Europe. that's just not good. And so therefore you want to make sure you comply with the requirements as much as you possibly can. At least seven hours at 16…Now there's other key GDPR terms and one is pseudonym Meninism see. Third grade. the sooner, yeah. I'm not even gonna bother saying that but it's basically using pseudonyms. And what it comes down to is as you have, like for an example bill Smith is patient 1, 2, 3, 4, 5. and it works to op use obfuscate data So you know that in the records. Bill is patient one through five And but you have to have a key or a cipher to be able to determine yep Patient 1, 2, 3, 4, 5 is bill Smith. but that's a really good way to suit a man randomized individuals and their. their names. And so then you can hide the actual patient data itself. Another one is anonymization and this is basically removing all relevant data about the person or their identity. a good example of this would be data masking And so you'd be using in SQL table. So for an example you would say, input would be bill Smith 1 2, 3, 4 5 6, 7, 8, 9. for like in the case of United States it'd be a social security number And let's just say that would be a really bad way of identifying somebody by the way Don't don't do that. even if you're going to randomize somebody just just don't do that. the output would be then Jennifer Smith, 9 8 7 6 5 4 3 2 months. Okay. That is is good but it really causes lots of challenges with that so you have to have a cipher to understand how to reconnect the dots. And that's that's where you really kind of gets confusing, but it's a way to totally randomize or anonymized that individual you would not know who they are unless you have the cipher unless you have a way to understand and how to reconnect everything together…Now as we deal with data reminisce some things to understand around this This is how the data that's remaining after media has been erased. And we kind of talked about that briefly and the cybersecurity integration piece of this. it's residual data after a full eraser of disk. So if you go and you do a full ratio of it, and you wipe it there's still data potentially remanent on. that device. You have to have a way to how do you deal with that and how do you remove that? so that's the residual data after your full disc exposure. Now there are serious problems especially with today's tools that you can do Cause you can find out if you say well I'm just going to do the standard format. Start out star. the the size of these disks it will take you forever in some cases also, if it doesn't always erase the data you just erase the pointers of the data. So if you can go back and find tools that can go out and actually pull this data out of the disc. that can be very valuable So, this is why it's important that you honestly if you have any sort of sensitive data just Newcomb or shred them, that as a better and then run a hammer through them. I can't run the hammer through them putting a nail through them something like that. But it comes into data leakage and data loss You will get that by having data remnants. there's also ghost images on computers and CRT monitors If you're CRT. these are really old which is a cathode Ray too when they're the green kind of things. those CRT monitors. If they've had a burn in for a long time say the data hasn't it's just always like a display screen. It will leave on the photo. I can't remember how they call it but it's basically it's a phosphorus type. Front end and it excites it And when it does that it leaves an image, a ghost image on the monitor. if you're really old like me you've probably seen that. And so therefore what ends up happening is is you can actually have a data sensitivity that is exposed. Now I don't know how many more CRTs are out there and available to people They are an extremely inefficient way and they're very. The power hungry They suck a lot of power. So, but they are they do still exist I'm sure of it. Could you see him I walk into Goodwill in the United States and I see those in our the Goodwill's and area that they give away things to people donate devices and things and clothes, and then people can come in and buy this stuff And that money goes to, the underprivileged people. so Goodwill has a lot of time to see our team monitors in there that people have given away. but those things are like way old and they're they don't work that well but…people still use them So you understand that ghost images on computers…Now there's a process to remove it We talked about this a little bit earlier about degaussing again these are powerful binds to destroy the typical magnetic drives and they are important There's also the handheld to Gaza right That's you do not have horseplay, no horseplay with the browser Just don't do it. physical destruction These are the jaws of deaths and death and you basically run your magnetic drive through this and it chews it up into shredded pulverized pieces of metal. so that's a really good way to make sure no one gets it. and it's also highly recommended for yourself State drives run everything that you don't want through there that you don't want to exist. Run it through that the jaws of death, and it will destroy that stuff So it will it will destroy almost any media product out there. worst comes to worst get a hammer and beat the living Dickens out of it If you can't put it in the jaws of death like a sledgehammer and just smash it to pieces. Ah that's a good way to destroy it as well. when you're erasing it delete the operation This is basically a delete operation on the file or media type And what I said like I mentioned before, It really only removes the pointer or the file locations not the data itself It's just guessed How is the data how do you find the data through that pointer? So, racing is just not a bad not a good idea at all. recommend that you actually do some level of software to do a complete overwrite which will overwrite the ones and zeros to all ones. but when the size of the SSD or the size of the drives today these like mega terabyte drives, it will take for AVOR. To do that So. it's almost just as easy just to destroy the drive itself unless you really really really want to reuse it again…we talked about clearing This is an override process and there's ways that you can get a there's some great websites out there on how to clear it. and you can buy that software specifically for clearing those devices. Again I gotta be careful on again a one to two terabyte device. it will take a long time. to overwrite this process for the media to be reused. so you have to just decide is it really worth it or not? you can write it basically writes a single character over the entire disc and there are very various tools to do this purging more intense form of Clara media to be reused. what it does is it then writes ones and zeros like in like seven different passes. So clearing at one time is one thing and then purging it and basically writing over it multiple times. that's if typically in the government if we were going to reuse something what we would do. Is we would you do the DOD standard which would then in turn override it like seven times before you could actually reuse it? But realistically these things are so cheap today that Dennis drives that it's almost better off just, just shredding it and going out and buying a new one. just because you'll spend more time from an opportunity cost standpoint clearing these things then to just go ahead and shred it and start all over…Transporter data flows this is a previous domains around trans border and you're going to have more and more personal data is moving from nation to nation And, and so therefore this, you have to be able to manage it and to be able to understand how this all works. Well there was an organization that through that they came to a con consensus and is called the organization for economic cooperation and development O E C D. And there's the key provisions that are in there of these 30 member states that said to how we do transporter data flows How do you do that And then how do you manage that…this was issued in 1980 and I know back then 1980, the internet was pretty small it did exist Al gore invented it, but it did exist. And so therefore what ended up happening was, the the data flows were pretty, pretty tight, pretty small today's world man They are flowing everywhere Data does not stay in one location It goes everywhere. And so therefore the. These a lot of these laws are a lot of these thoughts are a little bit dated and antiquated, but bottom line. is is there are data. trans transferred border data flows around how to you maintain and manage the personal data…Now there's eight driving principles of the O E C D. And one is a collection limitations It's a collection of personal data should be limited and not be, get gathered and garner too much. It should be obtained by Lee legal and fair methods There's no. basically siphoning data back on people without a legal or without That a proper way of doing that. the data quality It means that it should be kept complete You shouldn't take snippets of the data It should be maintained in the wholeness of it. One thing around that is if people cherry pick specific like you can say just even saying news news media all all the news media do it in some form. Is a conversation may occur and they'll take a piece of that a snippet of that conversation, and it will be taken out of context and therefore it gives a married different perspective And you can do that with data, whether it's video audio or just actually written forms. So it needs to be kept complete and it needs to be consistent with the purpose how it's being used. purpose selection notification to the person, purpose or person around collecting their information You need to let them know that Hey, I'm siphoning off your data I hope you're okay with that. they need to be able to know that Yeah I'm taking it I'm copying it It's okay Right You don't mind. and again this is at the time of collected and for the specific purpose of why you're doing it…Use limitations they need to have consent of the person or the law of 40 authority to disclose data. how are you disclosing it Do you have approval to do that? Do you notice notify the data's used for purposes stated in a different manner than what you disclosed So I'm going to use them for my research project Oh wait Then I send them to the sun or the national Inquirer on something that you said Yeah that's not right That's going to go badly for everybody Just don't do that. security standards basically do you have reasonable safeguards in place to protect the data? And do you have openness? When you develop your practices and policies were ground the data. be communicated What are you going to do with it How are you going to manage it? what do you how are you going to share it And do you have policies to protect it? the individuals should be. Be having individual participation as it relates to what do they want to do? and especially as it relates to personal data how. Are they okay with their data going across transporter…And then accountability organizations are accountable to ensure they comply with other principles as well. When they're dealing with the cross border data transfers. Okay So that's all I have for the CIS is P training Let us roll into the exam questions. Alright CISSP exam questions domain two…Okay Here's a question for domain two. What is the most correct term When an administrator is removing sensitive data from a system before putting it back into a less secure environment? Letter a. Erasing, let her be purging. Letter C clearing. Letter D. overriding and the answer is. See clearing clearing is an overriding process for immediate so that it can not be recovered once it is quote unquote cleared. Now we talked about before, clearing is a very important part Now if you are going to be working on the DOD standard and you want to have to make sure the data's completely erased, then you could purge the data with doing multiple overwrites. But clearing will be sufficient. in many cases especially if it's kept within the organization. you can just clear the device Now if you're going to be moving the device. to a different location than you'd want to look at purging the system…Next question. What is the following is the most secure method of destroying data on a hard disk drive in HDD, we have formatting. We have degaussing. You have destruction. And we have deleting what is the most secure way of destroying the data? And the answer is…C. destruction. All of them We'll delete the data in some form or another They will they'll all delete it and take care of it. But to ensure it's fully nuked and fully destroyed, you should are basically it's…de. Dead Yeah it's shredded. you should destroy it And that's really only physical destruction of the system itself will be the best method when making sure that the device there's the data is not available to individuals. So again that's a good one to think about destruction. All right. Let's move on…All right These are the links ISC squared study guide Quizlet. Also so there's some training from Thor teaches O E. D rainbow books and G X a. All right I hope you enjoyed this training from reduce cyber.