课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Data de-identification

Data de-identification

- [Instructor] One way that many organizations seek to protect themselves against accidental disclosures of personal information is to remove all identifying information from data sets when that identifying information is not necessary to meet business requirements. Deidentification is the process of moving through a data set and removing data that may be individually identifying. For example, you would certainly want to remove names, social security numbers, and other obvious identifiers. However, simple data deidentification is often insufficient to completely safeguard information. The reason for this is that you can often combine seemingly innocuous fields to uniquely identify an individual. A study done at Carnegie Mellon University analyzed three fields commonly retained in deidentified data sets, zip code, date of birth, and gender. You wouldn't think that any one of these fields when used alone would allow you to identify someone. After all, a lot of people live in the same…

内容