CramX Logo

"Tom is working on a report that contains employees' names, home addresses, and salary. Which of the following is Tom prohibited from doing with the report? A. E-mailing it to a colleague who needs to provide missing data B. Storing it in his locked desk drawer after working hours C. Using his home computer to print the report while teleworking D. Encrypting it"
12 months agoReport content

Answer

Full Solution Locked

Sign in to view the complete step-by-step solution and unlock all study resources.

Step 1:
Let's solve this problem step by step, focusing on data privacy and protection principles.

Step 2:
: Identify the Sensitive Information

The report contains: - Employees' names - Home addresses - Salary information These are considered personally identifiable information (PII) and confidential data that require careful handling.

Step 3:
: Analyze Each Option for Potential Privacy Violations

- $$\text{Risk Level}: \text{Low}
Option A: E-mailing to a colleague - Sending sensitive personal information via email without proper encryption is a significant privacy risk - This could potentially expose confidential employee data to unauthorized access Option B: Storing in a locked desk drawer - Physical security is an acceptable method of protecting sensitive documents - A locked drawer prevents unauthorized physical access Option C: Printing on home computer while teleworking - Using a personal computer introduces potential security vulnerabilities - Home networks may not have the same security protections as office networks Option D: Encrypting the document - Encryption is a recommended method for protecting sensitive data - Adds a layer of digital security to prevent unauthorized access

Step 4:
: Determine the Prohibited Action

The most problematic action is Option A: E-mailing the report to a colleague without proper safeguards.

Final Answer

Key Principles: - Protect personally identifiable information - Use secure methods of data transmission - Limit access to confidential documents - Follow organizational data privacy policies