Isc^2 Flashcards
An data about an individual that could be used to identify them.
PII
Personally a identifiable Information
Information regarding one’s health status
PHI
Protected Health Information
Includes trade secrets, research, business plans, and intellectual property
Classified Sensitive Information
Level of importance assigned to information by its owner or the purpose of denoting its need for protection.
Sensitivity
Something you now
Passwords or phrases
Something you have
Tokens, memory cards, smart cards
Something you are
Biometrics, measurable characteristics
Process to prove the identity of the request or
Authentication
Protection against an individual falsely denying having performed a particular action.
Non-repudiation
A measure of the extent to which an entity is threatened by a potential circumstance or event
Risk
Something in need of protection
ASSET
A gap or weakness in those protection efforts
Vulnerability
Something or someone that aims to exploit a vulnerability to thwart protection efforts.
Threat
Taking no action to reduce the likelihood of a risk occurring
Risk Acceptance
Decision to attempt to eliminate the risk entirely
Risk avoidance
Prevent or reduce the possibility of a risk event or it’s impact
Risk mitigation
Passing the risk onto another party
Risk Transfer
A method of risk analysis that is based on the assignment of a descriptor such as low medium or high
Qualitative Risk Analysis