Objectives 5.5 - Privacy and Sensitive Data Concepts Flashcards
What are 4 examples of organizational consequences of data breaches?
Reputation damage, Identify theft, fines, IP (intellectual property) theft
What are some potential consequences of reputation damage due to data breaches?
- Opinion of organization becomes negative
- Can have an impact on products and services
- Can impact stock prices
What are some potential consequences of identity theft due to data breaches?
- Company/customer information may become public
- May require public disclosure
- Credit monitoring costs
What are some potential consequences of fines due to data breaches?
- Lawsuit settlements that could cripple the company financially
What are some potential consequences of IP theft due to data breaches?
- Stealing company secrets
2. Can put a company OUT OF BUSINESS
What are important takes regarding public notification of breaches?
- Refer to the security breach laws. Check with your state or country for guidance
- May allow delays for criminal investigations
What are some traits of a proprietary data classification?
- Data that is the property of an organization
- May also include trade secrets
- Often data unique to an organization
What are some traits of a PII (Personally Identifiable Info) data classification?
- Data that can be used to identify an individual
2. Can be Name, Date of Birth, Mother’s maiden name, biometric info, etc.
What are some traits of a PHI (Personal Health Info) data classification?
- Health information associated with an individual
2. Health status, health care record
What are some traits of a public data classification?
- No restrictions. It is public knowledge
What are some traits of a Private/Classified/Restricted/Internal Use Only data classification?
- Restricted access, may require an NDA
What are some traits of a sensitive data classification?
- Intellectual property, PII, PHI
What are some traits of a confidential data classification?
- Very sensitive, needs approval to view
What are some traits of a critical data classification?
- Data should always be available
What are some traits of a financial data classification?
- Internal company financial information
2. Customer financial details