Section outline

  • Lesson 8. Data Cybersecurity, Hygiene, and Prospects (Big Data, AI). Personal Data Protection (GDPR, Ukrainian Legislation), Backup, Two-Factor Authentication. Overview of Data Science, Big Data, and AI Analytics Fields

    Objective: formation of a holistic system of knowledge, legal awareness and practical engineering skills in the field of information protection, regulatory compliance, cyber hygiene and orientation in modern technological trends in data engineering. The student must master the evolution of security architectures from outdated perimeter protection to the Zero Trust Architecture (ZTA) model, the fundamental principles of international and national regulatory regulation (GDPR, Laws of Ukraine No. 2297-VI, No. 2163-VIII, ISO/IEC 27001), as well as comprehend the triad of interaction between the areas of Big Data, Data Science and AI-analytics. During the training, special attention is paid to understanding and comparative analysis of the three engineering principles of ZTA (Explicit Verification, Least Privilege Access/JIT/JEA, Assume Breach with micro-segmentation and Data-in-Transit / Data-at-Rest encryption), mastering the concepts of Privacy by Design, Data Minimization and differentiation of the roles of the data controller/processor and the rights of subjects (in particular, the right to be forgotten and access). Students should learn to practically implement personal and corporate cyber hygiene protocols: configure phishing-resistant multi-factor authentication (FIDO2/Passkeys, TOTP), manage credentials through password managers using the Zero-Knowledge model, anonymize and tokenize PII arrays, and design fault-tolerant backup schemes using the extended 3-2-1-1-0 strategy using immutable storage (Immutable Storage / WORM). An important analytical and prognostic result is the formation of the ability to evaluate modern technological vectors of analytics development (real-time streaming processing based on Kafka/Flink, hybrid Data Lakehouse architecture, vector DBMS and RAG systems), as well as to critically analyze and mitigate legal and security risks when deploying corporate analytical pipelines.