SSP Legal & Ethical Compliance 3 — Questions and Answers
Question 1: A security practitioner is asked by an executive to share confidential employee investigation records with HR without a formal request. The correct action is to:
- Share the records since HR is an internal department
- Require a formal written request following established protocols (Correct answer)
- Refuse permanently regardless of circumstances
- Share only a verbal summary to avoid documentation
Correct answer: Require a formal written request following established protocols
Confidential investigation records must be shared only through formal, documented requests to maintain chain of custody and legal defensibility.
Question 2: Which legal concept holds an employer responsible for wrongful acts committed by employees within the scope of their employment?
- Negligent hiring
- Respondeat superior (Correct answer)
- Proximate cause
- Strict liability
Correct answer: Respondeat superior
Respondeat superior is the legal doctrine under which employers are vicariously liable for employee actions performed within the scope of employment.
Question 3: Under GDPR, what is the maximum timeframe to notify supervisory authorities of a personal data breach that poses risk to individuals?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires that personal data breaches posing risk to individuals be reported to the supervisory authority within 72 hours of discovery.
Question 4: A security professional who witnesses evidence being destroyed during an ongoing investigation should:
- Attempt to recover the evidence personally before reporting
- Document what was observed and immediately report to legal counsel (Correct answer)
- Wait to see if additional evidence surfaces before acting
- Dispose of any related records to avoid contamination
Correct answer: Document what was observed and immediately report to legal counsel
Observing evidence destruction must be immediately documented and reported to legal counsel to preserve legal options and comply with spoliation rules.
Question 5: The concept of 'duty of care' in security management primarily means:
- Providing free medical care to security staff
- Taking reasonable precautions to protect persons from foreseeable harm (Correct answer)
- Caring for lost-and-found property on behalf of visitors
- Maintaining care for classified documents
Correct answer: Taking reasonable precautions to protect persons from foreseeable harm
Duty of care obligates security professionals to take reasonable measures to protect individuals from harm that is reasonably foreseeable.
Question 6: Which act requires federal agencies and contractors to implement minimum security standards for information systems?
- Gramm-Leach-Bliley Act
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- Computer Fraud and Abuse Act (CFAA)
- Electronic Communications Privacy Act
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA requires federal agencies and their contractors to develop, document, and implement security programs to protect federal information systems.
Question 7: What is the primary ethical principle violated when a security consultant recommends a product from a vendor in which they hold undisclosed financial interest?
- Confidentiality
- Non-maleficence
- Conflict of interest (Correct answer)
- Proportionality
Correct answer: Conflict of interest
An undisclosed financial interest in a recommended vendor creates a conflict of interest, violating professional ethical standards.
A security practitioner is asked by an executive to share confidential employee investigation records with HR without a formal request.
The correct action is to: