Modules Flashcards
What does CIA stand for?
Confidentiality, Integrity, and Availability
Define Confidentiality
Confidentiality relates to permitting authorized access to information, while at the same time protecting information from improper disclosure
Define Availability
Availability means that systems and data are accessible at the time users need them
Define Integrity
Integrity is the property of information whereby it is recorded, used and maintained in a way that ensures its completeness, accuracy, internal consistency and usefulness for a stated purpose
What is the security professional’s obligation?
to regulate access—protect the data that needs protection yet permit access to authorized individuals
Confidentiality is a difficult balance to achieve because
When many system users are guests or customers, and it is not known if they are accessing the system from a compromised machine or vulnerable mobile application
What is Personally Identifiable Information (PII)?
It is a term related to the area of confidentiality. It pertains to any data about an individual that could be used to identify them.
Other terms related to confidentiality are….
protected health information (PHI), which is information regarding one’s health status, andclassified or sensitive information, which includes trade secrets, research, business plans and intellectual property
What is sensitivity?
a measure of the importance assigned to information by its owner, or the purpose of denoting its need for protection
What is sensitive information?
information that if improperly disclosed (confidentiality) or modified (integrity) would harm an organization or individual
Example of sensitive information:
In many cases, sensitivity is related to the harm to external stakeholders; that is, people or organizations that may not be a part of the organization that processes or uses the information.
How does the National Institute of Standards and Technology (NIST) define confidentiality?
It is the characteristic of data or information when it is not made available or disclosed to unauthorized persons or processes
What is Personally Identifiable Information (PII)?
Any information that can be used to distinguish or trace an individual’s identity, such as name, Social Security number, date and place of birth, mother’s maiden name, or biometric records; and any other information that is linked or linkable to an individual, such as medical, educational, financial and employment information.
protected health information (PHI)
Information regarding health status, the provision of healthcare or payment for healthcare as defined in HIPAA (Health Insurance Portability and Accountability Act).
classified or sensitive information
Information that has been determined to require protection against unauthorized disclosure and is marked to indicate its classified status and classification level when in documentary form.
sensitivity
A measure of the importance assigned to information by its owner, for the purpose of denoting its need for protection.