MoIS4 CH 12 Review Questions
1. What is the difference between criminal law and civil law?
Civil law embodies a wide variety of laws pertaining to relationships between and among
2. What is tort law and what does it permit an individual to do?
Tort law is a subset of civil law that allows individuals to seek recourse against others in the
3. What are the three primary types of public law?
4. Which law amended the Computer Fraud and Abuse Act of 1986, and what did it
change?
The National Information Infrastructure Protection Act of 1996 amended the Computer Fraud
5. What is the USA PATRIOT Act? When was it initially established and when was it
significantly modified?
The USA PATRIOT Act was initially enacted in 2001 as a mechanism to provide the United
6. What is privacy in the context of information security?
In the context of information security, privacy is individuals’ right to guard their information
7. What is another name for the Kennedy-Kassebaum Act (1996), and why is it important to
organizations that are not in the health care industry?
The Kennedy-Kassebaum Act is also known as the Health Insurance Portability and
8. If you work for a financial service organization (such as a bank or credit union), which
law from 1999 affects your use of customer data? What other effects does it have?
The Gramm-Leach-Bliley (GLB) Act of 1999 affects how financial service organizations use
9. Which 1997 law provides guidance on the use of encryption?
The Security and Freedom through Encryption Act of 1997 provides rules and guidelines on the
10. What is intellectual property? Is it offered the same protection in every country? What
laws currently protect intellectual property in the United States and Europe?
Intellectual property is any material or words created by individuals on their own free time or at
11. What is a policy? How does it differ from a law?
A policy is a formalized description of acceptable and unacceptable employee behavior, which,
12. What are the three general categories of unethical and illegal behavior?
The three general categories of unethical and illegal behavior that organizations and society
13. What is the best method for preventing illegal or unethical behavior?
14. Of the professional organizations discussed in this chapter, which has been in existence
the longest time? When was it founded?
15. Of the professional organizations discussed in this chapter, which is focused on auditing
and control?
The Information Systems Audit and Control Association (ISACA) focuses on auditing and
16. What is the stated purpose of the SANS organization? In what ways is it involved in
professional certification for InfoSec professionals?
SANS is dedicated to the protection of information and systems by promoting GIAC
17. Which U.S. federal agency sponsors the InfraGard program? Which agency has taken
control of the overall National Infrastructure Protection mission?
The Federal Bureau of Investigation’s National Infrastructure Protection Center sponsors the
18. What is due care? Why would an organization want to make sure it exercises due care in
its usual course of operations?
Due care is a company taking measures to make sure that every employee knows what is
19. What should an organization do to deter someone from violating policy or committing a
crime?
Successful deterrence requires the institution of severe penalties of which people are aware, the
20. How does due diligence differ from due care? Why are both important?
Due diligence requires that an organization make a valid and ongoing effort to protect others.
This differs from due care in that due diligence is a constantly active role within a company. Due