1
1

00:00:00,180  -->  00:00:01,590
<v ->In this section of the course,</v>
2

2

00:00:01,590  -->  00:00:04,500
we're going to cover non-technical data and privacy controls
3

3

00:00:04,500  -->  00:00:06,960
by returning to Domain 1, Security Operations
4

4

00:00:06,960  -->  00:00:09,060
and Domain 2, Vulnerability Management
5

5

00:00:09,060  -->  00:00:13,020
specifically focusing on objectives 1.1 and 2.5.
6

6

00:00:13,020  -->  00:00:14,640
Now, objective 1.1 states
7

7

00:00:14,640  -->  00:00:16,740
that you must be able to explain the importance of system
8

8

00:00:16,740  -->  00:00:19,860
and network architecture concepts in security operations.
9

9

00:00:19,860  -->  00:00:21,390
And objective 2.5 states
10

10

00:00:21,390  -->  00:00:23,490
that you must be able to explain concepts related
11

11

00:00:23,490  -->  00:00:26,400
to vulnerability response, handling and management.
12

12

00:00:26,400  -->  00:00:27,600
Now, if you've taken the time to look
13

13

00:00:27,600  -->  00:00:29,490
at the objectives provided by CompTIA,
14

14

00:00:29,490  -->  00:00:31,920
you may be wondering why am I linking this section
15

15

00:00:31,920  -->  00:00:33,240
to these two objectives?
16

16

00:00:33,240  -->  00:00:35,910
Because the terms data classification, data types,
17

17

00:00:35,910  -->  00:00:36,750
legal requirements
18

18

00:00:36,750  -->  00:00:39,000
and many others are not distinctly listed
19

19

00:00:39,000  -->  00:00:41,490
within the sub bullets underneath these objectives.
20

20

00:00:41,490  -->  00:00:43,530
But that doesn't mean that they're not going to show up
21

21

00:00:43,530  -->  00:00:44,880
on exam day.
22

22

00:00:44,880  -->  00:00:45,720
If you look at the bottom
23

23

00:00:45,720  -->  00:00:48,600
of page two of the objectives PDF provided by CompTIA,
24

24

00:00:48,600  -->  00:00:50,580
you're going to see the following statement.
25

25

00:00:50,580  -->  00:00:52,590
Quote, "The list of examples provided
26

26

00:00:52,590  -->  00:00:55,410
in bulleted formats are not exhaustive lists.
27

27

00:00:55,410  -->  00:00:58,830
Other examples of technologies, processes or tasks pertain
28

28

00:00:58,830  -->  00:01:01,590
to each objective may also be included on the exam
29

29

00:01:01,590  -->  00:01:04,680
although not listed or covered in this objectives document."
30

30

00:01:04,680  -->  00:01:05,790
End of quote.
31

31

00:01:05,790  -->  00:01:07,140
Now, this is why we are talking
32

32

00:01:07,140  -->  00:01:09,840
about these non-technical data and privacy controls
33

33

00:01:09,840  -->  00:01:13,770
in this section of the course under objectives 1.1 and 2.5.
34

34

00:01:13,770  -->  00:01:17,010
Because these terms and concepts do link directly back
35

35

00:01:17,010  -->  00:01:19,890
to these tasks listed underneath the objectives that state
36

36

00:01:19,890  -->  00:01:21,990
that you must explain the importance of system
37

37

00:01:21,990  -->  00:01:24,990
and network architecture concepts in security operations
38

38

00:01:24,990  -->  00:01:27,240
and to be able to explain concepts related
39

39

00:01:27,240  -->  00:01:30,150
to vulnerability response, handling and management.
40

40

00:01:30,150  -->  00:01:32,850
So even though these concepts aren't clearly listed out
41

41

00:01:32,850  -->  00:01:35,730
as sub bullets underneath the objectives here, trust me,
42

42

00:01:35,730  -->  00:01:38,130
they are things that the exam will ask you about.
43

43

00:01:38,130  -->  00:01:39,390
And they actually used to be listed
44

44

00:01:39,390  -->  00:01:41,790
out directly underneath these different objectives
45

45

00:01:41,790  -->  00:01:43,560
in older versions of the exams.
46

46

00:01:43,560  -->  00:01:45,210
And I can tell you I have seen these types
47

47

00:01:45,210  -->  00:01:47,760
of questions still being asked in the latest version
48

48

00:01:47,760  -->  00:01:49,500
of the CySA+ exam
49

49

00:01:49,500  -->  00:01:51,750
which is why we're going to include them here to ensure
50

50

00:01:51,750  -->  00:01:53,880
that you understand how to answer these questions.
51

51

00:01:53,880  -->  00:01:56,790
And we do that by linking them to these two objectives.
52

52

00:01:56,790  -->  00:01:58,680
So as we move through this section,
53

53

00:01:58,680  -->  00:02:00,540
we're going to start out by discussing the different types
54

54

00:02:00,540  -->  00:02:02,460
of data classification that's being used
55

55

00:02:02,460  -->  00:02:04,260
within different organizations.
56

56

00:02:04,260  -->  00:02:05,880
Then we'll discuss the different types
57

57

00:02:05,880  -->  00:02:07,530
of data that's used in organizations
58

58

00:02:07,530  -->  00:02:08,790
and the various legal requirements
59

59

00:02:08,790  -->  00:02:10,650
that affect our data systems.
60

60

00:02:10,650  -->  00:02:12,077
Next, we'll discuss the policies
61

61

00:02:12,077  -->  00:02:15,000
for processing personal data within an organization
62

62

00:02:15,000  -->  00:02:17,190
as well as discussing data retention standards
63

63

00:02:17,190  -->  00:02:18,780
and the secure disposal of data
64

64

00:02:18,780  -->  00:02:21,510
when it's no longer needed by your organization.
65

65

00:02:21,510  -->  00:02:23,820
Then we're going to talk about data ownership,
66

66

00:02:23,820  -->  00:02:26,400
data sharing and privacy agreements that are going to be used
67

67

00:02:26,400  -->  00:02:28,740
by different organizations around the globe.
68

68

00:02:28,740  -->  00:02:30,630
And finally, we're going to take a short quiz
69

69

00:02:30,630  -->  00:02:32,790
to see what you learned during this section of the course
70

70

00:02:32,790  -->  00:02:34,590
and review those quiz questions fully
71

71

00:02:34,590  -->  00:02:35,490
to ensure you can explain
72

72

00:02:35,490  -->  00:02:37,410
why the correct answers were correct.
73

73

00:02:37,410  -->  00:02:39,930
So let's start diving through all the different types
74

74

00:02:39,930  -->  00:02:41,040
of non-technical data
75

75

00:02:41,040  -->  00:02:43,230
and privacy controls that you're going to experience
76

76

00:02:43,230  -->  00:02:44,730
in this section of the course.
