CC-in-the-Cloud / General

Common Criteria in the Cloud Technical Community
https://cc-in-the-cloud.github.io/
MIT License
6 stars 1 forks source link

Guidance doc section 3.1 - Useful Terms #66

Closed GallagherTom closed 11 months ago

GallagherTom commented 1 year ago

Suggested terms for cloud:

Also, I'd recommend changing the title of 3.1 since we already have a section called "Introduction"

tstodart commented 1 year ago

Please provide term definitions. The second use of 'Introduction' is referring to the first chapter in most PP's. I could change the first one to 'Preface' or something else.

compgeeksquires commented 11 months ago

Possible Data sovereignty definitions: From https://www.techtarget.com/whatis/definition/data-sovereignty: "Data sovereignty is the concept that information which has been converted and stored in binary digital form is subject to the laws of the country in which it is located."

longer option: from https://cloudian.com/guides/data-protection/data-sovereignty-in-the-cloud-key-considerations/ "Data sovereignty refers to the laws applicable to data because of the country in which it is physically located. The legal rights of data subjects (any individual whose personal information is being gathered, retained, or processed), and data protection requirements, depend on the location in which their data is stored. Accordingly, organizations will have different responsibilities for data in different geographical locations.

Data sovereignty is distinct from data localization and data residency:

Data localization refers to a governmental policy that prohibits organizations from transferring data outside a specific location. It is a special case of data sovereignty. Data residency is a decision by businesses to store data in a specific geographical location. Organizations might store data in a specific location to avoid legal requirements, take advantage of tax regimes, or for performance reasons. Once an organization chooses a location for its data, it is subject to data sovereignty—the laws applicable in that region."

bharveyTX commented 11 months ago

Migrating data sovereignty claims to Scheme Guidance issue.