暗記メーカー
ログイン
IAS 1_2
  • Zorro Roronoa

  • 問題数 42 • 9/12/2024

    記憶度

    完璧

    6

    覚えた

    16

    うろ覚え

    0

    苦手

    0

    未解答

    0

    アカウント登録して、解答結果を保存しよう

    問題一覧

  • 1

    an unauthorized or unintentional disclosure of confidential information.

    data breach

  • 2

    ensures that information is reliable as well as accurate; and

    integrity

  • 3

    All personal data shared over the Internet is subject to privacy issues. Most websites publish a privacy policy that details the website's intended use of collected online and/or offline collected data.

    interest privacy

  • 4

    relates to the responsibility of those who have data to control who can use that data.

    access

  • 5

    ensures that data is both available and accessible to satisfy business needs.

    availability

  • 6

    The organization must view privacy as primarily being characterized by personal control and free choice.

    Respect for user privacy

  • 7

    In dealing with the privacy of PII, two (2) new concepts have emerged: privacy by design (PbD) and privacy engineering. • The goal of ___________ is to take privacy requirements into account throughout the system development process, from the conception of a new IT system through detailed system design, implementation, and operation.

    privacy by design

  • 8

    Information privacy is considered an important aspect of information sharing. With the advancement of the digital age, personal information vulnerabilities have increased

    aspect of privacy

  • 9

    is information that can be used to distinguish or trace an individual’s identity, such as: o Information about birth, race, religion, weight, activities, geographic indicators, employment information, medical information, education information, and financial information; o Personal characteristics, including photographic images, x-rays, fingerprints, or biometric image; and o Asset information, such as Internet Protocol (IP) or media access control (MAC) address or other host- specific persistent static identifier that consistently links to a particular person or a small, well-defined group of people.

    personal identifiable information

  • 10

    All medical records are subject to stringent laws that address user access privileges. By law, security and authentication systems are often required for individuals that process and store medical records.

    medical privacy

  • 11

    Privacy protections should be core, organic functions, not added on after a design is complete.

    privacy embeded to the design

  • 12

    involves taking account of privacy during the entire life cycle of ICT (information and communications technology) systems

    privacy engineering

  • 13

    focus on the types of capabilities the system needs to demonstrate the implementation of an organization’s privacy policies and system privacy requirements.

    privacy engineering

  • 14

    the stealing of data or confidential information by electronic means, including ransomware and hacking.

    cyber attack

  • 15

    which side circle is the privacy?

    left

  • 16

    concerns the collection and use of data about individuals.

    privacy

  • 17

    Financial information is particularly sensitive, as it may easily use to commit online and/or offline fraud

    financial privacy

  • 18

    which side is security?

    right

  • 19

    includes a disciplined, structured, and flexible process for organizational asset valuation; security and privacy control selection, implementation, and assessment; system and control authorizations; and continuous monitoring. Risk management is an iterative process,

    risk management

  • 20

    Right of an individual to be left alone and have control over their data o Procedures for proper handling, processing, collecting, and sharing of personal data o Compliance with data protection laws

    elements of data privacy

  • 21

    ensures that data is accessed only by authorized individuals.

    confidentiality

  • 22

    PbD is an approach that anticipates privacy issues and seeks to prevent problems before they arise

    proactive, not reactive,preventive not remedial

  • 23

    is an expectation of loss expressed as the probability that a particular threat will exploit a particular vulnerability with a particular harmful result

    security risk assessment

  • 24

    are system requirements that have privacy relevance. System privacy requirements define the protection capabilities provided by the system, the performance and behavioral characteristics exhibited by the system, and the evidence used to determine that the system privacy requirements have been satisfied. Privacy requirements are derived from various sources, including laws, regulations, standards, and stakeholder expectations.

    privacy requirements

  • 25

    This principle encompasses two concepts. The terms end-to-end and life cycle refer to the protection of PII from the time of collection through retention and destruction. During this life cycle, there should be no gaps in the protection of the data or accountability for the data. The term security highlights that security processes and controls are used to provide not just security but privacy

    life cycle protection

  • 26

    The objective of a ___________________ is to enable organization executives to determine an appropriate budget for privacy and, within that budget, implement the privacy controls that optimize the level of protection.

    privacy risk assesment

  • 27

    what model is this?

    cia triad

  • 28

    are safeguards or countermeasures prescribed for an information system or an organization that are designed to protect the confidentiality, integrity, and availability of its information and to meet a set of defined security requirements

    security controls

  • 29

    is a part of the data protection area that deals with the proper handling of data, with the focus on compliance with data protection regulations.

    data privacy

  • 30

    PbD seeks to assure users and other stakeholders that privacy-related business practices and technical controls are operating according to state commitments and objectives.

    visibility and transparency

  • 31

    refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be directly ascertained by the entity holding the information

    personal data

  • 32

    relates to the responsibility of those who collect data to ensure that the data is correct.

    accuracy

  • 33

    name of this layer?

    privacy engineering

  • 34

    This principle requires an organization to ensure that it only processes the data that is necessary to achieve its specific purpose and that PII is protected during collection, storage, use, and transmission.

    privacy as the default

  • 35

    is a model designed to guide an organization’s policies on information security. The elements of the triad are considered the three most crucial components of security. The following are the three (3) elements of data security.

    cia triad

  • 36

    These are system requirements that have privacy relevance.

    privacy requirements

  • 37

    relates to who owns the data.

    property

  • 38

    includes a set of standards and different safeguards and measures that an organization is taking to prevent any third party from unauthorized access to digital data or any intentional or unintentional alteration, deletion, or data disclosure.

    data security

  • 39

    is an analysis of how information is handled: to ensure handling conforms to applicable legal, regulatory, and policy requirements regarding privacy;

    privacy impact asessment

  • 40

    name of this layer ?

    privacy by design

  • 41

    Designers should seek solutions that avoid requiring a trade-off between privacy and system functionality or between privacy and security.

    full functionality

  • 42

    the process of ingesting, storing, organizing, and maintaining the data created and collected by an organization.

    data management