6.4.3 data movement

Cards (9)

  • To protect data at rest, enterprises can do what 3 main things?
    Encrypt the data
    Network security (firewalls, access control)
    Physical security (surveillance, locks)
  • An effective method for protecting data at rest in enterprises especially held in storage servers is, creating consistent data policies.
    These often include things such as classifying certain data as sensitive and automatically encrypting and protecting it
  • Encryption protects data as the meaning of data is hard to decipher without an encryption key
  • Data can be categorised into 3 types:
    Data at rest
    Data in use
    Data in transit
  • Data at rest is data that is stored and not moving. Data at rest means the data is stored on some form of non-volatile storage
  • Data in use is data that is being actively used and/or processed by a digital system
  • Is data in volatile storage in use or at rest?
    In use
  • Data in motion is data being transferred from one hardware location to another, such as from one computer to another over the internet, or data from computer to server over the internet
  • What standard most applies to data security?
    ISO/IEC 27040