Module 6 Flashcards
(8 cards)
Legal risks
Not complying with privacy laws (state, federal and international)
Not fulfilling contractual commitments
Reputational risks
Damaging trust in the brand: Organizations can face both legal enforcement and reputational harm if they do not adhere to their stated privacy policies
Operational risks
Affecting efficiency
Inhibiting use of personal information that benefits the organization and customers
Investment risks
Hampering the ability of the organization to receive an appropriate return on its investments in information, IT and information processing programs
four distinct steps in Developing an information management program
Discover, Build, Communicate and Evolve.
The steps in the development of an incident response program include
Preparation, identification, containment, eradication, recovery and lessons learned.
The classification level
defines the clearance of individuals who can access or handle that data, as well as the baseline level of protection that is appropriate for that data.
Data sensitivity levels
confidential, proprietary, sensitive, restricted and public data