✔✔Privacy Maturity Model - ✔✔Provides a standardized reference for companies to use
in assessing the level of maturity of their privacy programs.
✔✔Privacy Operational Life Cycle - ✔✔Focused on refining and improving privacy
processes, this model continuously monitors and improves the privacy program, with
the added benefits of a life cycle approach to measure (assess), improve (protect),
evaluate (sustain) and support (respond), and then start again.
✔✔Privacy Program Framework - ✔✔An implementation roadmap that provides the
structure or checklists (documented privacy procedures and processes) to guide the
privacy professional through privacy management and prompts them for the details to
determine all privacy-relevant decisions for the organization.
✔✔Privacy Threshold Analysis - ✔✔One tool used to determine whether a PIA should
be conducted.
✔✔Privacy-Enhancing Technologies - ✔✔Privacy technology standards developed
solely to be used for the transmission, storage and use of privacy data. Examples
include Platform for Privacy Preferences (P3P) and Enterprise Privacy Authorization
Language (EPAL).
✔✔Protect - ✔✔The second of four phases of the privacy operational life cycle. It
provides the data life cycle, information security practices and Privacy by Design
principles to "protect" personal information.
✔✔Protected Health Information - ✔✔Any individually identifiable health information
transmitted or maintained in any form or medium that is held by a covered entity or its
business associate; identifies the individual or offers a reasonable basis for
identification; is created or received by a covered entity or an employer, and relates to a
past, present or future physical or mental condition, provision of healthcare or payment
for healthcare to that individual.
, ✔✔Purpose Specification - ✔✔A fair information practices principle, it is the principle
stating that the purposes for which personal data are collected should be specified no
later than at the time of data collection and the subsequent use limited to the fulfillment
of those purposes or such others as are not incompatible with those purposes and as
are specified on each occasion of change of purpose.
✔✔Respond - ✔✔The fourth of four phases of the privacy operational life cycle. It
includes the respond principles of information requests, legal compliance, incident-
response planning and incident handling. The "respond" phase aims to reduce
organizational risk and bolster compliance to regulations.
✔✔Return on Investment - ✔✔An indicator used to measure the financial gain/loss (or
"value") of a project in relation to its cost. Privacy ROI defines metrics to measure the
effectiveness of investments to protect investments in assets.
✔✔Security Safeguards - ✔✔A fair information practices principle, it is the principle that
personal data should be protected by reasonable security safeguards against such risks
as loss or unauthorized access, destruction, use, modification or disclosure of data.
✔✔Social Engineering - ✔✔A general term for how attackers can try to persuade a user
to provide information or create some other sort of security vulnerability.
✔✔Stakeholders - ✔✔Individual executives within an organization who lead and "own"
the responsibility of privacy activities.
✔✔Strategic Management - ✔✔The first high-level task necessary to implementing
proactive privacy management through three subtasks: Define your organization's
privacy vision and privacy mission statements; develop privacy strategy; and structure
your privacy team.
✔✔Sustain - ✔✔The third of four phases of the privacy operational life cycle. It provides
privacy management through the monitoring, auditing, and communication aspects of
the management framework.
✔✔US-CERT - ✔✔A partnership between the Department of Homeland Security and
the public and private sectors intended to coordinate the response to security threats
from the Internet. As such, it releases information about current security issues,
vulnerabilities and exploits via the National Cyber Alert System and works with software
vendors to create patches for security vulnerabilities.
✔✔US-CERT IT Security Essential Body of Knowledge - ✔✔Fourteen generic
information security practice competency areas, including: Digital Security; Digital
Forensics; Enterprise Continuity; Incident Management; IT Security and Training
Awareness; IT Systems Operation and Maintenance; Network and Telecommunications
Security; Personnel Security; Physical and Environmental Security; Procurement;