Security Law & Liability Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Law & Liability flashcards as text
Under the federal Electronic Communications Privacy Act (ECPA), employer monitoring of employee electronic communications at work is generally:
Answer: Permissible when employees have been notified and have consented via policy
ECPA's 'consent exception' and 'ordinary course of business' exception allow employer monitoring when employees have been given clear notice and consent through acceptable-use policies.
A security investigator installs a hidden audio recorder in an employee break room without consent. In a 'two-party consent' state, this is:
Answer: Unlawful — all-party consent states require everyone present to consent to recording
All-party (two-party) consent states require consent from every person being recorded; covert audio recording in such states without consent violates state wiretapping law.
Video surveillance of a workplace restroom or changing area would most likely:
Answer: Constitute a serious privacy violation and potentially a criminal offense
Employees retain a reasonable expectation of privacy in restrooms and changing areas; covert video surveillance of these areas violates privacy laws and anti-voyeurism statutes in virtually every jurisdiction.
Chain of custody in a security investigation refers to:
Answer: The documented, unbroken record of who collected, handled, and stored evidence
A proper chain of custody documents every person who handled evidence from collection through trial to ensure integrity and admissibility.
Which federal law governs the privacy of health information that a security investigator might encounter during an internal investigation at a hospital?
Answer: Health Insurance Portability and Accountability Act (HIPAA)
HIPAA protects individually identifiable health information; accessing or disclosing it without authorization during an investigation can create significant legal exposure.
A security investigator conducting a background check for a pre-employment screening must comply with which federal statute?
Answer: The Fair Credit Reporting Act (FCRA)
The FCRA regulates consumer reporting agencies and mandates disclosure, authorization, and adverse-action notices when consumer reports are used for employment purposes.
Under the Computer Fraud and Abuse Act (CFAA), a security investigator who accesses a company computer system beyond their authorized level of access may be:
Answer: Criminally and civilly liable for exceeding authorized computer access
The CFAA prohibits unauthorized or excess-authorization access to protected computers and provides for both federal criminal penalties and civil remedies.