Information Theft

From Open Risk Manual
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.

Definition

Information Theft is the fraudulent acquisition of information assets (data) by parties external or internal to the organization. Such information may be stored in physical form (e.g. paper records) or digitally, in which case it is a type of IT Risk

Examples

There is a wide variety of attack vectors, depending on the storage/transmission mechanisms, for example

  • Document Theft / Copying
  • Database Theft
  • Credit Card Number, ATM Spoofing, PIN Capturing

See Also