PRA and PSCS Flashcards
The objective of a … is to enable organization executives to determine an appropriate budget for privacy and, within that budget, implement the privacy controls that optimize the level of protection
Privacy Risk Assessment
are safeguards or countermeasures prescribed for an information system or an organization that are designed to protect the confidentiality, integrity, and availability of its information
Security controls
Individual privacy cannot be achieved solely through securing personal identifiable information. Hence, both security and privacy controls are needed.
True
are technical, physical, and administrative (or management) measures employed within an organization to satisfy privacy requirements
Privacy controls
Privacy controls might result in:
- Removing the threat source
- Changing the likelihood that the thread can exploit a vulnerability by reducing or eliminating the vulnerability or by changing the amount of PII collected or the way it is processed
- Changing the consequences of a privacy event