Matching Pairs Layers of SecurityOnline version Match the definition with the correct term. by Quintasia Hurt 1 risk assessment 2 risk mitigation 3 social engineering 4 Integrity 5 Defense in depth 6 risk management 7 confidentiality 8 attack surface 9 Availability 10 Access control 11 CIA The process of restricting access to a resource to only permitted users, applications, or computer systems. The consistency, accuracy, and validity of data or information. One of the goals of a successful information security program is to ensure that data is protected against any unauthorized or accidental changes. Describes a resource being accessible to a user, application, or computer system when required. The exposure, the reachable and exploitable vulnerabilities that a system or technology has. Taking steps to reduce the likelihood or impact of a risk. Identifies the risks that might impact your particular environment. A method used to gain access to data, systems, or networks, primarily through misrepresentation. This technique typically relies on the trusting nature of the person being attacked. confidentiality, integrity, availability The process of identifying, assessing, and prioritizing threats and risks. The characteristic of a resource ensuring access is restricted to only permitted users, applications, or computer systems.