Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
1
Lecture Outline
Chapter 15: HRIS Privacy and Security
CHAPTER OBJECTIVES
After completing this chapter, you should be able to describe the following:
The importance of information security and privacy in today’s technology
intensive and information-driven economy
INTRODUCTION
Information privacy and security are particularly important issues for HRIS because unlike many
other organizational systems, an HRIS includes a great deal of confidential data about
employees, such as Social Security numbers, medical data, bank account data, salaries, domestic
partner benefits, employment test scores, and performance evaluations.
Doing this is much more complex than it was 30 years ago. Consider that most computers at that
time were mainframes that were secured in a central physical location, with very few HR staff
having access to them. If an HR staff member had access to the mainframe, it was through
“dumb” terminals with limited functionalities, and access was easily restricted through physical
access and passwords. Due to this closed environment, there was little threat of security
breaches or vulnerabilities being exploited.
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
2
However, starting in the 1990s, as computer networks became more common, threats to
information security became more involved due to presence of enterprise-wide systems.
In view of the growing concern about identity theft and the security of employment information
in HRIS, a number of states (e.g., AK, CA, FL, HI, IL, LA, MO, NY, SC, and WA) passed
privacy laws requiring organizations to adopt reasonable security practices to prevent
unauthorized access to personal data (Privacy Protections in State Constitutions, 2012).
Software vendors such as Oracle, are aware of the potential for security breaches and offer
multiple security models (e.g., Standard HRIS Security and Security Groups Enabled Security)
that enable an administrator to set up HRIS security specifically for an organization. This means
that the software allows companies to determine the kind of data access and responsibility each
employee has.
EMPLOYEE PRIVACY
The U.S. Fair Labor Standards Act of 1938 requires employers to maintain basic information
on all employees, including Social Security number, address, gender, occupation, pay, and hours
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
3
Unauthorized Access to Information
One reason that employees are concerned about the storage of data in an HRIS is that they fear
that these systems may allow unauthorized access to their private information. For example,
employees may perceive that if users have access to their Social Security numbers or bank data,
they will experience identity theft. In fact, some reports indicate that identity theft is the primary
Unauthorized Disclosure of Information
Another concern about the use of HRIS is that employees may perceive that these systems allow
for the unauthorized disclosure of information about them to others. For example, research
Data Accuracy Problems
Employees are also troubled about data accuracy because HRIS may contain inaccurate or
outdated information about them. Not surprisingly, individuals are often unaware that data in
these systems are inaccurate, and many organizations do not give them the opportunity to review
or correct data stored in HRIS.
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
4
Stigmatization Problems
Employee are often uneasy about the use of HRIS, especially when they feel that networked data
may lead to them to be stigmatized or deeply discredited in employment.
Lack of Privacy Protection Policies
Despite the widespread use of HRIS and growing concerns about the (a) unauthorized access, (b)
unauthorized release, (c) data accuracy, and (d) use of data to stigmatize employees, many
companies have not established fair information management policies to control the use and
release of employee information.
COMPONENTS OF INFORMATION SECURITY
Brief Evolution of Security Models
The complexity of the networked environment in which HR data is captured, stored, and utilized
means that personnel transactions and information processing are increasingly more vulnerable
The McCumber Cube provides a graphical representation of the architectural approach widely
used in information security. It examines not only the characteristics of the information to be
protected but also the context of the information state. The Cube allows an analyst to identify the
information flows within an HRIS, view it for important security-relevant factors, and then map
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
5
SECURITY THREATS
What kind of threats are our organizational security practices protecting us from? In security, it is
important to “know your enemy.” The following are common security threats:
Threat Sources
Human error: When an HRIS is not well designed, developed, and maintained and
employees are not adequately trained, there is a high potential threat of security breaches.
Other “Internal” Attackers: Many businesses hire contract workers, who work for the
organization for a short period. Contract workers usually gain temporary access to various
critical areas of an organization. This creates risks almost identical to those created by
employees.
External Hackers: Another significant threat is the penetration of organizational computer
systems by hackers. A hacker is defined as someone who accesses a computer or computer
network unlawfully. Such attacks, often termed intrusions, can be particularly dangerous
because once the hacker has successfully bypassed the network security, he or she is free to
damage, manipulate, or simply steal data at will.
Theft: The value of information can be much higher than the price of hardware and software.
With contemporary advances in technological developments, a relatively small computer
chip (e.g., a USB device) can easily store over 100 GB of data. For example, the State of
Hawaii’s HR department had medical records stolen when doctors’ offices of two doctors
servicing workers compensation claims were burglarized.
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
6
(e.g., a hacker) is hired to break into a specific computer or computer network to steal or
delete data and information. Cyberterrorists often send a threatening e-mail stating that they
will release some confidential information, exploit a security leak, or launch an attack that
could harm a company’s systems or networks.
Software Threats
A computer virus is a type of malware that works by inserting a copy of itself onto a
computer or device (e.g., smartphone) and then becoming part of another program. It can
attach itself to files without the user’s knowledge and duplicate itself by executing infected
files. When successful, a virus can alter data, erase or damage data, create a nuisance, or
inflict other damage.
Blended threats: These threats propagate both as viruses and worms. They can also post
themselves on websites for people to download unwittingly.
Trojan is another type of malware that usually hides inside e-mail attachments or files and
infects a user’s computer when attachments are opened or programs are executed. Trojans are
Information Policy and Management
It is important that organizations have policies and procedures in place to protect employee data.
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
7
There are two mechanisms though which this can occur: fair information management policies
and strong security practices.
However, one state, California, has recently passed a law that protects the privacy of employee
records in private-sector organizations (Privacy Protection in State Constitutions, 2012).
In addition, multinational organizations should also consider the privacy practices in the
countries in which they operate. The challenge for organizations is that every country takes a
different perspective on protecting employee information privacy, and your organization will
need to be familiar with all the applicable laws in each country in which you operate.
EFFECTIVE INFORMATION SECURITY PRACTICES
The second way that organizations need to protect employee data is through their security
practices.
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
8
For effective implementation of security, organizations usually follow established security
standards, such as ISO/IEC 27000 series.
This series focuses on areas such as access control, security management, good practices,
and protection of health-related information. Almost all aspects of the ISO/IEC 27000
series mesh with HRIS. For example, it is standard practice to require HR employees to
Several best practices have been proposed to ensure that employee data is secured and employee
privacy is protected. These include the following:
Adopt a comprehensive information security and privacy policy.
Store sensitive personal data in secure HRIS and provide appropriate encryption.
CHAPTER SUMMARY
Instructor Resource
Kavanagh and Johnson, Human Resource Information Systems: Basics, Applications, and Future Directions, 4e
SAGE Publishing, 2018
9
Although it is clear that HRIS have numerous benefits in organizations, this chapter considers
some recent issues associated with their use, including employee privacy and information
security. In particular, the chapter considers (a) practices that may affect individuals perceptions