Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
Chapter 15: HRIS Privacy and Security
Test Bank
Multiple Choice
1. Which of the following is considered a common security threat?
a. human error
b. damage by employees
c. hackers
d. all of these
2. ______ are best described as people who accesses a computer or computer network
unlawfully.
a. Hackers
b. Viruses, worms, and trojans
c. Information thieves
d. Disgruntled employees
3. Information security breaches cost approximately ______ annually.
a. $78 million
b. $45 billion
c. $10 billion
d. $100 billion
4. Which of the following is not considered a “best practice” that HR managers should
consider to secure information security and privacy?
a. Train users on how to securely use and handle the equipment, data, and software.
b. Make backup copies of data files and programs.
c. Do not allow passwords to be shared. Change passwords frequently.
d. Require employees to take sensitive material home with them so that it is not left at
the office.
5. According to the text, approximately what percentage of employers monitor what
employees are posting to external blogs and social networking sites?
a. 25%
b. 30%
c. 75%
d. 100%
6. The McCumber Cube for Data Privacy has three dimensions. Which of the following
is NOT a dimension that is used to organize a privacy policy?
a. desired information goals
b. countermeasures
c. state of information
d. use of information
7. Which of the following is NOT considered a threat to security?
a. human error
b. disgruntled employees and ex-employees
c. other “internal” attackers
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
d. none of these
8. Which of the following is NOT considered a software threat to security?
a. worms
b. spyware
c. trojan virus
d. file corruption
9. Which state has passed a law protecting employee records in private organizations?
a. California
b. Ohio
c. New York
d. Oregon
10. Which of the following is NOT a recommended privacy policy statement?
a. Adopt a comprehensive information security and privacy policy.
b. Store sensitive personal data in secure HRIS, and provide appropriate encryption.
c. Dispose of documents properly, or restore persistent storage equipment.
d. Conduct focus groups with selected employees.
11. Which type of security threat is the most widespread, affecting almost 90% of
companies?
a. computer fraud
b. phishing
c. denial of service
d. theft of hardware components, such as storage cards
12. Which of these is NOT a well-known worm” threat?
a. Slammer
b. Code Red
c. MyDoom
d. MyPirate
13. Which is NOT a symptom of spyware on an employee’s computer?
a. invasion of privacy
b. appropriation of personal information
c. interference with the speed and responsiveness of the computer
d. proliferation of pop-up ads
True/False
1. All companies have been affected by computer-based fraud, such as data processing
or data entry routines that are modified.
2. Viruses and trojans are common external security threats to organizations and often
come in e-mail attachments.
3. A hacker is defined as someone who accesses a computer or computer network
unlawfully.
4. Three main goals of information security are to achieve confidentiality, integrity, and
availability within an HRIS.
5. Integrity ensures that information is created and modified in an authorized manner.
6. Phishing is known as the illegal scheme where victims usually receive e-mail
messages that appear to come from an authentic source with which the victim does
business.
7. Human error and natural disasters are not considered viable threats to employee
privacy and data security.
Essay
1. What is meant by information security in HRIS?
3. What are some of the best practices that HR managers should consider to secure
information security and privacy? Be sure to list at least five best practices that were
discussed in class, as well as in your textbook.
4. Briefly list and describe the important goals and considerations of information
security.
5. There are many threats to information security. Please describe five information
security threats.
6. Describe cyberterrorism and how to at least control its impact.
7. What is meant by phishing?
8. What is the difference between a computer virus and spyware?