CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems
A retailer keeps a database of customer names, mobile numbers and purchase history. An employee with legitimate access copies the list and sells it to a marketing agency without the customers' consent. Which statement is correct from a database-security and cyber-law viewpoint?
The act breaches confidentiality and privacy even though the employee had access. Organisations should use role-based access, least privilege and audit logs to deter and trace insider misuse, and personal data protection obligations may apply to unauthorised disclosure.
- AAccess controls alone make the act lawful since the employee was authorised to view the data
- BThe act is a breach of confidentiality and privacy, so the organisation needs controls such as role-based access and audit logs, and the personal data protection obligations may be attractedCorrect
- COnly encryption at rest is relevant, and the act cannot be traced
- DThe act is not an issue because the data is stored in a relational database
Explanation
Authorisation to view data is not authority to disclose it for an unrelated purpose. Role-based access, activity logging and least privilege help prevent and trace insider misuse, and disclosure of personal data without consent attracts privacy and data protection consequences. Encryption at rest does not stop an authorised user from copying data.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems shows your real accuracy, how long you take and where you lose marks.
More Information Systems questions
- During a Business Impact Analysis (BIA) at a Hyderabad insurer, the team identifies the claims portal as a critical process. What is the pri…
- Kaveri Pharma's finance team signs its electronically filed returns using a digital signature certificate. Which statement correctly describ…
- The marketing function of an e-commerce firm uses customer purchase history to send targeted offers. Which information system component is c…
- An 'Orders' table in a Pune firm's database has a column 'CustomerID' whose values must match existing values in the 'Customers' table's pri…
- A Mumbai-based payments company wants to define the maximum amount of data loss, measured in time, that it can tolerate after a system failu…
- Which of the following is an application control, rather than a general IT control?