An IT technician conducting a file server audit discovers an unencrypted shared directory containing employee Social Security numbers, dates of birth, and personal home addresses. Which of the following data classifications best describes this information, and what security control must be implemented to maintain compliance?
- Personally Identifiable Information (PII); access must be restricted using access control lists and data must be encrypted.Cevap
- BProtected Health Information (PHI); the folder must be configured with HIPAA audit logging and biometric authentication.
- CCardholder Data (CHD); all files must be permanently sanitized to meet PCI-DSS post-authorization storage regulations.
- DPublicly Accessible Data; no encryption or access control is necessary because these fields are standard corporate directory items.
Cevap
Personally Identifiable Information (PII); access must be restricted using access control lists and data must be encrypted.
The correct response accurately identifies Social Security numbers, birth dates, and home addresses as Personally Identifiable Information (PII). PII encompasses any data that can directly or indirectly identify an individual. Compliance guidelines mandate restricting access to authorized personnel and encrypting the data at rest to prevent unauthorized disclosure.
Adım Adım Çözüm
Anahtar Kavram
Personally Identifiable Information (PII) Identification and Protection