Introduction
Based strictly on the provided historical exam context (from a Data Engineering paper) and acknowledging the complete absence of a syllabus for CY-703(B), the following short notes identify potential topical overlaps where Data Engineering concepts might intersect with Cyber Security Policies & Standards. This is a speculative extraction only. The core of CY-703(B) likely covers standards like ISO 27001, NIST CSF, GDPR, etc., which are not present in the provided question set.
UNIT 3: Short Notes (Based on Limited External Context)
1. Data Governance & Security Policy Alignment
Definition: The overall management of data availability, usability, integrity, and security within an enterprise. In a cybersecurity context, it defines the policies, standards, and procedures that ensure data is handled securely and in compliance with regulations.
| Aspect | Description | Cybersecurity Link |
|---|---|---|
| Policy Framework | Sets rules for data classification, ownership, and usage. | Directly feeds into Information Security Policies (e.g., data handling rules). |
| Standards & Procedures | Defines technical controls (encryption, access logs). | Implements security controls from frameworks like ISO 27001 (A.8, A.9, A.12). |
| Compliance & Auditing | Ensures adherence to laws (GDPR, HIPAA). | Core function of Security Governance, Risk & Compliance (GRC). |
| Data Lineage | Tracking data flow from source to destination. | Critical for incident response, data breach analysis, and proving compliance. |
Exam Tip: In a security policy exam, "Data Governance" is often discussed as the strategic layer that mandates technical security controls. Be ready to link it to specific policy documents (e.g., Data Classification Policy, Data Retention Policy).
2. Secure Copy Protocol (SCP) as a Secure Data Transfer Control
Definition: A network protocol based on SSH (Secure Shell) for secure file transfer between hosts. It provides encryption and authentication, making it a secure alternative to legacy protocols like FTP.
| Feature | Security Implication |
|---|---|
| Encryption | All data (including passwords) is encrypted during transit. Prevents eavesdropping. |
| Authentication | Uses SSH keys or passwords. Supports strong authentication mechanisms. |
| Integrity | SSH protocol provides data integrity checks. |
| Use in Policies | Often mandated in Secure Data Transfer Policies for internal/external data movement. |
Pseudo-Code for SCP Command (Conceptual):
1. Initiate SSH connection to remote host.
2. Authenticate using private key or password.
3. Request file transfer (push or pull).
4. Stream file data over encrypted SSH channel.
5. Verify transfer completion and close connection.
Common Pitfall: SCP is deprecated in favor of more modern protocols like SFTP or rsync over SSH due to limitations (e.g., no directory listing, no resume). A strong security policy may recommend SFTP but still reference SCP for legacy system compatibility.
3. Zachman Framework: An Enterprise Architecture Lens
Definition: A schema for organizing enterprise architecture artifacts (descriptions of the enterprise) into a 6x6 matrix. It is not a methodology but a framework for classification.
| Perspective (Rows) | What (Data) | How (Function) | Where (Network) | Who (People) | When (Time) | Why (Motivation) |
|---|---|---|---|---|---|---|
| Executive (Scope) | What entities? | What processes? | What locations? | Who is involved? | What timeline? | Why objectives? |
| Business (Model) | Semantic model | Business process | Business locations | Organization chart | Event schedule | Business rules |
| System (Design) | Logical data model | System process | Distributed system | Security roles | Processing cycle | Design constraints |
| Technology (Detail) | Physical data model | Technology process | Physical network | User accounts | Timing details | Technology rules |
| Detailed (Function) | Data definitions | System programs | Node addresses | User profiles | Job schedules | Operational rules |
| Operation (Inst.) | Actual data | Actual processes | Actual network | Actual people | Actual schedule | Actual motivations |
Cybersecurity Relevance:
-
Provides a holistic view for identifying where security controls must be placed (e.g., "Who" row for roles/permissions, "Where" for network zones).
-
Helps in gap analysis for security architecture against business requirements.
-
Often used as a scoping tool in large-scale security policy development.
Exam Tip: Know the 6 interrogative categories (What, How, Where, Who, When, Why) as columns and the 6 stakeholder perspectives (Executive, Business, System, Technology, Detailed, Operation) as rows. Be prepared to explain how it helps structure security policies across an organization.
4. Data Lake Patterns & Security Implications
Definition: A data lake is a vast, raw data repository storing structured, semi-structured, and unstructured data. "Patterns" refer to architectural approaches for its implementation.
| Pattern | Description | Primary Security Concerns |
|---|---|---|
| Centralized Lake | Single, massive repository. | Single point of failure/attack. Requires robust perimeter security, fine-grained access. |
| Distributed Lake | Multiple lakes (by domain/region). | Consistent policy enforcement across distributed systems. Complex access management. |
| Lakehouse | Combines data lake flexibility with warehouse structure. | Unified security model for both raw and curated data. Metadata security is critical. |
Key Security Policy Requirements for Data Lakes:
-
Unified Access Control: Centralized identity (e.g., LDAP/AD) with attribute-based access control (ABAC) to raw data.
-
Data Classification & Tagging: Automated tagging of sensitive data (PII, PHI) at ingestion.
-
Audit Logging: Comprehensive logging of all data access and queries (for detective controls).
-
Encryption: At-rest (storage layer) and in-transit (network layer) encryption.
-
Governance Integration: Security policies must integrate with data catalog and lineage tools.
Common Pitfall: Assuming a data lake's "schema-on-read" nature eliminates the need for security. Raw data is often more sensitive (contains PII, logs). Policies must enforce security before data lands in the lake.
5. Data Lineage for Security & Compliance
Definition: The complete lifecycle of data: origins, movements, transformations, and usage. In security, it's critical for traceability and impact analysis.
| Type | How it Works | Security Use Case |
|---|---|---|
| Pattern-Based Lineage | Infers lineage by analyzing data patterns (e.g., column names, value distributions) between source and target. | Useful for legacy systems where metadata is poor. Can detect unauthorized data flows. |
| Lineage by Tagging | Uses data tags/labels (e.g., "PII", "Confidential") attached to datasets/tables. | Enables automated policy enforcement (e.g., block export of "PII"-tagged data). |
| Technical Lineage | Captured from ETL jobs, SQL queries, APIs. | Precise for breach investigation: "Which system accessed this sensitive column?" |
Security Policy Integration:
-
Regulatory Proof: Lineage demonstrates data residency and processing consent (GDPR Art. 30).
-
Access Review: Shows who accessed what data and when.
-
Impact Analysis: Before applying a patch or changing a system, lineage shows which security controls (e.g., encryption, DLP) might be affected.
Exam Tip: Distinguish between technical lineage (exact, from logs) and business lineage (high-level, for compliance). Security policies often require both for different stakeholders (auditors vs. engineers).
Critical Analysis of Provided Context
The provided past paper questions are entirely from Data Engineering. The only direct security mentions are:
-
"Secure Copy Protocol (SCP)" – A specific technical control.
-
"Data Governance" – A strategic function that includes security policy.
-
"Zachman Framework" – An enterprise architecture tool that can scope security.
Conclusion for CY-703(B) Preparation:
-
Do NOT study Lambda/Kappa Architecture, Data Lifecycle, Web Scraping, or ETL in depth for this cybersecurity policy exam.
-
DO focus on how data-centric concepts (Governance, Lineage, Architecture) are governed by security policies and standards (ISO 27001, NIST Privacy Framework, GDPR).
-
The real UNIT 3 for CY-703(B) almost certainly covers:
-
Specific Security Standards: ISO/IEC 27001, NIST Cybersecurity Framework (CSF), COBIT.
-
Compliance Regulations: GDPR, HIPAA, PCI-DSS, India's DPDP Act.
-
Policy Types & Structure: Acceptable Use Policy, Incident Response Policy, Data Classification Policy.
-
Risk Management Frameworks: OCTAVE, FAIR.
-
Final Recommendation: Obtain the actual syllabus and past papers for CY-703(B). The provided context is from a different subject (C Data Engineering) and will mislead your preparation. Use the above notes only to understand the intersection of data management and security policy, not as a substitute for the core syllabus.