Matching Pairs Layers of SecurityOnline version Match the definition with the correct term. by Quintasia Hurt 1 Access control 2 Integrity 3 CIA 4 Defense in depth 5 social engineering 6 Availability 7 risk mitigation 8 risk assessment 9 risk management 10 attack surface 11 confidentiality The process of identifying, assessing, and prioritizing threats and risks. The process of restricting access to a resource to only permitted users, applications, or computer systems. A method used to gain access to data, systems, or networks, primarily through misrepresentation. This technique typically relies on the trusting nature of the person being attacked. Identifies the risks that might impact your particular environment. Describes a resource being accessible to a user, application, or computer system when required. confidentiality, integrity, availability The consistency, accuracy, and validity of data or information. One of the goals of a successful information security program is to ensure that data is protected against any unauthorized or accidental changes. The characteristic of a resource ensuring access is restricted to only permitted users, applications, or computer systems. Taking steps to reduce the likelihood or impact of a risk. The exposure, the reachable and exploitable vulnerabilities that a system or technology has.