Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
Chapter 15: HRIS Privacy and Security
Test Bank
Multiple Choice
1. Which of the following is considered a common security threat?
A. human error
B. damage by employees
C. hackers
D. all of these
2. ______ are best described as people who access a computer or computer network
unlawfully.
A. Hackers
B. Viruses, worms, and Trojans
C. Information thieves
D. Disgruntled employees
3. What federal law places restrictions on the collection, use, or dissemination of data
about private-sector job applicants?
A. the National Labor Relations Act
B. the Fair Labor Standards Act
C. no law
D. the Family and Medical Leave Act
Johnson, Human Resource Information Systems, 5e
4. Which privacy rights do employees have in the European Union?
A. the right to be informed about the collection, storage, and release of data
B. the right to access their data
C. the right to ensure that the data are accurate, and rectify or erase data that are
inaccurate
D. all of the above
5. How has concern about information security changed over the years?
A. There is less concern now than there was 30 years ago.
B. There is more concern now than there was 30 years ago.
C. There is the same amount of concern now as there was 30 years ago.
D. Information security has never been a concern.
6. The McCumber Cube for Data Privacy has three dimensions. Which of the following
is NOT a dimension that is used to organize a privacy policy?
A. desired information goals
B. countermeasures
C. state of information
D. use of information
7. Which of the following is NOT considered a threat to security?
A. human error
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
B. disgruntled employees and ex-employees
C. other “internal” attackers
D. All of these are considered as threats to security.
8. Which of the following is NOT considered a software threat to security?
A. worms
B. spyware
C. Trojans
D. file corruption
9. Which state has passed a law protecting employee records in private organizations?
A. California
B. Ohio
C. New York
D. Oregon
10. Which of the following is NOT a recommended privacy policy statement?
A. adopt a comprehensive information security and privacy policy
B. store sensitive personal data in secure HRIS and provide appropriate encryption
C. dispose of documents properly or restore persistent storage equipment
D. conduct focus groups with selected employees
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
11. Which type of security affects almost 90% of companies?
A. computer-based fraud
B. phishing
C. denial of service
D. theft of hardware components, such as storage cards
12. Which of these is NOT a well-known “worm” threat?
A. Slammer
B. Code Red
C. MyDoom
D. Mypirate
13. Which is NOT a symptom of spyware on an employee’s computer?
A. invasion of privacy
B. appropriation of personal information
C. interference with the speed and responsiveness of the computer
True/False
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
1. All companies have been affected by computer-based fraud, such as data processing
or data entry routines that are modified.
2. Viruses and Trojans are common external security threats to organizations and often
come in e-mail attachments.
3. One of the best practices for information security is “never dispose of documents.”
4. There are no federal or state laws that prevent employers from reviewing the internet
or social media sites for applicant information.
5. Integrity ensures that information is created and modified in an authorized manner.
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
6. Phishing is known as the illegal scheme where victims usually receive email
messages that appear to come from an authentic source with which the victim does
business.
7. Human error and natural disasters are not considered threats to employee privacy
Essay
1. What is the definition of information security?
2. Describe the McCumber Cube approach to privacy.
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
3. What are some of the best practices that HR managers should consider to secure
that employee data are secured and employee privacy is protected? Be sure to list at
least five best practices.
4. What are the data processing principles that employers in the European Union must
comply with?
Johnson, Human Resource Information Systems, 5e
5. What are the sources of security threats?
6. Describe cyberterrorism.
Johnson, Human Resource Information Systems, 5e
SAGE Publishing, 2021
7. What is meant by phishing?
8. What is the difference between a computer virus and spyware?