Soru

Zorluk: OrtaData Governance, Classification, and Privacy Controls

A healthcare organization is auditing its data handling practices prior to migrating patient health records to a cloud service provider. Which of the following statements accurately describe operational duties of a data custodian and appropriate privacy preservation techniques for this migration? (Select TWO.)

  1. Implementing technical encryption controls at rest and managing routine data backup schedules according to established policyCevap
  2. B
    Determining the formal data classification level of patient records and authorizing user access requests
  3. Replacing direct personal identifiers in analytical datasets with reversible surrogate keys kept in a segregated, secure locationCevap
  4. D
    Categorizing technical data encryption mechanisms as deterrent administrative controls within the security framework

Cevap

The correct statements are implementing technical encryption controls and managing backup schedules according to policy, and replacing direct personal identifiers with reversible surrogate keys stored separately (pseudonymization).
The statements involving technical implementation of encryption and backups as well as applying pseudonymization to analytical datasets are correct. Data custodians handle technical system maintenance under policy guidelines, and pseudonymization protects privacy by storing key mappings separately from processed data.

Adım Adım Çözüm

1
Differentiate between data owner and data custodian operational responsibilities.
Identified that hands-on infrastructure maintenance (encryption, backups) belongs to the custodian, whereas policy decisions and classification authority belong to the owner.
Data custodians maintain the operational environment and enforce technical controls defined by data owners.
2
Evaluate privacy-enhancing technology definitions.
Confirmed that separating identifying key data from processed datasets constitutes pseudonymization.
Pseudonymization reduces privacy risk by ensuring data cannot be linked to a data subject without additional separately stored key details.
3
Verify security control functional classification.
Determined that data encryption is a technical preventive safeguard.
Encryption uses cryptographic logic to prevent unauthorized disclosure of plain text data.

Anahtar Kavram

Data Custodian Operational Duties vs Data Owner Responsibilities and Pseudonymization Privacy Controls
Bu soruyu puanla