4. Which of the following is not considered a “best practice” that HR managers should
consider to secure information security and privacy?
a. Train users on how to securely use and handle the equipment, data, and software.
b. Make backup copies of data files and programs.
c. Do not allow passwords to be shared. Change passwords frequently.
d. Require employees to take sensitive material home with them so that it is not left at
the office.
5. According to the text, approximately what percentage of employers monitor what
employees are posting to external blogs and social networking sites?
a. 25%
b. 30%
c. 75%
d. 100%
6. The McCumber Cube for Data Privacy has three dimensions. Which of the following
is NOT a dimension that is used to organize a privacy policy?
a. desired information goals
b. countermeasures
c. state of information
d. use of information
7. Which of the following is NOT considered a threat to security?
a. human error
b. disgruntled employees and ex-employees
c. other “internal” attackers