QS0025-03: Information Security Policy Flashcards
QS0025-01: Information Security Policy
How is Personally Identifiable Information (PII) defined?
Personally Identifiable Information, PII, is any information that can be associated with a unique individual or used to identify, locate, or contact a unique individual.
QS0025-01: Information Security Policy
What are four information security classifications defined in the Information Security Policy?
Restricted, Confidential, Internal, and Public.
QS0025-01: Information Security Policy
Who is responsible for protecting PII data hosted on behalf of Lablynx clients?
Any persons with access to, use or communicate any LabLynx information.
QS0025-01: Information Security Policy
How is the “Restricted” information defined?
Information of a strategic nature that, if disclosed without authorization, would cause substantial, severe, or irreparable damage to LabLynx or its relationships.
QS0025-01: Information Security Policy
How must the physical media, such as hard copy records, be protected?
Physical media, such as hard copy records, must be protected with locks or equivalent controls.
QS0025-01: Information Security Policy
What actions may be taken if sensitive information is improperly disclosed?
Unauthorized disclosure of LabLynx information or failure to adequately protect that information may lead to disciplinary action, including termination or release.
QS0025-01: Information Security Policy
Summarize the “Record and Information” Owner’s responsibilities?
Identify security classifications, periodic risk assessments, and access