Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems

A retailer keeps a database of customer names, mobile numbers and purchase history. An employee with legitimate access copies the list and sells it to a marketing agency without the customers' consent. Which statement is correct from a database-security and cyber-law viewpoint?

The act breaches confidentiality and privacy even though the employee had access. Organisations should use role-based access, least privilege and audit logs to deter and trace insider misuse, and personal data protection obligations may apply to unauthorised disclosure.

  1. AAccess controls alone make the act lawful since the employee was authorised to view the data
  2. BThe act is a breach of confidentiality and privacy, so the organisation needs controls such as role-based access and audit logs, and the personal data protection obligations may be attractedCorrect
  3. COnly encryption at rest is relevant, and the act cannot be traced
  4. DThe act is not an issue because the data is stored in a relational database

Explanation

Authorisation to view data is not authority to disclose it for an unrelated purpose. Role-based access, activity logging and least privilege help prevent and trace insider misuse, and disclosure of personal data without consent attracts privacy and data protection consequences. Encryption at rest does not stop an authorised user from copying data.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems shows your real accuracy, how long you take and where you lose marks.

More Information Systems questions