It never rains but it pours. Just as bosses and boards have finally sorted out their worst accounting and compliance troubles, and improved their feeble corporation governance, a new problem threatens to earn them – especially in America – the sort of nasty headlines that inevitably lead to heads rolling in the executive suite: data insecurity. Left, until now, to odd, low-level IT staff to put right, and seen as a concern only of data-rich industries such as banking, telecoms and air travel, information protection is now high on the boss’s agenda in businesses of every variety.

Several massive leakages of customer and employee data this year – from organizations as diverse as Time Warner, the American defense contractor Science Applications International Corp and even the University of California, Berkeley – have left managers hurriedly peering into their intricate IT systems and business processes in search of potential vulnerabilities.

“Data is becoming an asset which needs to be guarded as much as any other assets, says Haim Mendelson of Stanford University’s business school. “The ability to guard customer data is the key to market value, which the board is responsible for on behalf of shareholders.” Indeed, just as there is the concept of Generally Accepted Accounting Principles (GAAP), perhaps it is time for GASP, Generally Accepted Security Practices, suggested Eli Noam of New York’s Columbia Business School. “Setting the proper investment level for security, redundancy, and recovery is a management issue, not a technical one,” he says.

The mystery is that this should come as a surprise to any boss. Surely it should be obvious to the dimmest executive that trust, that most valuable of economic assets, is easily destroyed and hugely expensive to restore – and that few things are more likely to destroy trust than a company letting sensitive personal data get into the wrong hands.

The current state of affaires may have been encouraged – though not justified – by the lack of legal penalty (in America, but not Europe)for data leakage. Until California recently passed a law, American firms did not have to tell anyone, even the victim, when data went astray. That may change fast: lots of proposed data-security legislation is now doing the rounds in Washington, D.C. Meanwhile, the theft of information about some 40 million credit-card accounts in America, disclosed on June 17th, overshadowed a hugely important decision a day earlier by America’s Federal Trade Commission (FTC)that puts corporate America on notice that regulators will act if firms fail to provide adequate data security.

16. The statement “It never rains but it pours” is used to introduce

[A] the fierce business competition.    [B] the feeble boss-board relations.

[C] the threat from news reports.    [D] the severity of data leakage.

17. According to Paragraph 2, some organizations check their systems to find out

[A] whether there is any weak point.   [B] what sort

of data has been stolen.

[C] who is responsible for the leakage.   [D] how the potential spies can be located.

18. In bringing up the concept of GASP the author is making the point that

[A] shareholders’ interests should be properly attended to.

[B] information protection should be given due attention.

[C] businesses should enhance their level of accounting security.

[D] the market value of customer data should be emphasized.

19. According to Paragraph 4, what puzzles the author is that some bosses fail to

[A] see the link between trust and data protection. [B] perceive the sensitive of personal data.

[C] realize the high cost of data restoration.    [D] appreciate the economic value of trust.

20. It can be inferred from Paragraph 5 that

[A] data leakage is more severe in Europe.

[B] FTC’s decision is essential to data security.

[C] California takes the lead in security legislation.

[D] legal penalty is a major solution to data leakage.

16. 【正确答案】【D】

【解析】结构题,题干中的“is used to introduce”表明本题是结构题。本题考查考生对文章第一段内容的理解。题干中的信号句出自文章第一段第一句话中。文章第一段首先提到,这里从不下雨,但却下倾盆大雨,随后引出了人们面临的一个新问题——信息的不安全性,接着具体介绍了这个问题。这说明,这个句子被用来介绍信息不安全的问题。D为正确选项。A、B和C都是误解了作者的意图。

17. 【正确答案】【A】

【解析】细节题,题干中的“According to Paragraph 2”表明本题是事实细节题。本题考查考生对文章第二段内容的理解。题干中的信号词是“some organizations”,出自文章第二段中。文章第二段指出,好几次消费者和员工信息的重大泄密事件使得管理人员匆忙检查其复杂的信息系统和商业程序,以便寻找可能的弱点,接着介绍了发生泄密事件的机构。这说明,这些机构检查系统的目的是为了查明系统是否有弱点。A为正确选项。B和C与文意不符;D属于无中生有。

18. 【正确答案】【B】

【解析】细节题,题干中的“the author is making the point”表明本题是观点细节题。本题考查考生对文章第三段内容的理解。题干中的信号词是“GASP”,出自文章第三段第三句话中。文章第三段首先提到,保护消费者信息的能力是市场价值的关键因素,这是董事会应该为了股东的利益而承担的责任,接着指出,正如存在公认的会计原则观念一样,现在可能是采取公认的安全措施的时候了。这说明,作者认为,现在应该采取措施保护消费者的信息。B为正确选项。A和D不准确;C属于无中生有。

19. 【正确答案】【A】

【解析】细节题,题干中的“According to Paragraph 4”表明本题是事实细节题。本题考查考生对文章第四段内容的理解。文章第四段指出,对于所有老板来说,这可能是一个意外,对于最怀疑的管理人员来说,诚信被轻易破坏,而要恢复诚信却代价高昂,此外,很少有什么比一个公司听任敏感的个人信息落入不妥当人之手更可能破坏诚信的了。这说明,作者感到迷惑的是,这些老板宁可让敏感的个人信息落入不妥当人之手,也要保护诚信,说明他们不了解诚信与信息保护之间的关系。A为正确选项。D与文意相反;B和C明显与文意不符。

20. 【正确答案】【D】

【解析】推论题,题干中的“can be inferred”表明本题是推论题。本题考查考生对文章第五段内容的理解。文章前面的段落介绍了信息泄露问题,第五段指出,这类事情的现状可能受到缺乏有关信息泄露的法律处罚的激励,而这种情况可能迅速改变,随后提到了可能实施的相关法律。由此可知,法律手段可能是解决信息泄露问题的关键。D为正确选项。A和C属于无中生有;B与该段最后一句话的意思不符。








