2.Learning Aim A3 Flashcards

(22 cards)

1
Q

What is the primary purpose of the Data Protection Act (1998)?

A

To protect the privacy of individuals by ensuring that their personal information is processed in an ethical manner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What significant law replaced the Data Protection Act (1998) in the EU?

A

General Data Protection Regulations (GDPR) enforced on May 25, 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the maximum fine for breaching GDPR?

A

€20 million or 4% of a business’s annual turnover, whichever is largest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What body is responsible for investigating data protection violations in the UK?

A

Information Commissioners Office (ICO).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Fill in the blank: The Data Protection Act (1998) covers data stored on _______.

A

paper and audio data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What principle was added to the GDPR that was not in the Data Protection Act (1998)?

A

Accountability principle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does the Computer Misuse Act (1990) protect users against?

A

Theft and damage of information stored using IT systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the punishment for unauthorized access to computer material under the Computer Misuse Act?

A

Up to 2 years in prison and/or a large fine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False: The Computer Misuse Act (1990) only applies to successful hacking attempts.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What additional offence was added by the Police and Justice Act (2006)?

A

Making, supplying or obtaining anything which can be used in computer misuse offences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations (2000) allow organizations to do?

A

Monitor communications over their network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

List one of the purposes for which organizations can monitor communications under the Telecommunications Regulations.

A
  • To establish the existence of facts and ascertain compliance with regulations
  • In the interests of national security
  • To prevent or detect crime
  • To investigate or detect unauthorized use of the network
  • To secure and ensure the effective operation of the network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What three classes of fraud are defined in the Fraud Act (2006)?

A
  • Fraud by false representation
  • Fraud by failing to disclose information
  • Fraud by abuse of power
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the maximum punishment for fraud under the Fraud Act (2006)?

A

Up to 10 years imprisonment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the Health and Safety at Work Act (1974) require employers to do?

A

Perform a risk assessment and ensure the health, safety, and welfare of employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is one duty of employees under the Health and Safety at Work Act?

A

Take care of their own health & safety and that of others.

17
Q

What can the Health & Safety Executive do if a business is found guilty of an HSWA offence?

A

Impose an unlimited fine and/or a prison term of up to 2 years.

18
Q

Fill in the blank: The Health & Safety at Work Act is enforced by the _______.

A

Health & Safety Executive (HSE).

19
Q

What happened to the punishment for unauthorized access under the Police and Justice Act (2006)?

A

Increased to 2 years imprisonment.

20
Q

What is the consequence of breaching the Data Protection Act (1998)?

A

A fine of up to £500,000.

21
Q

What is a key feature of the accountability principle under GDPR?

A

Organizations must have appropriate measures and records to demonstrate compliance.

22
Q

True or False: The Computer Misuse Act (1990) only applies to traditional hacking.