Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Information Ethics


Published on

Published in: Technology, Education
  • This new site crushes dating! view profiles now! ■■■
    Are you sure you want to  Yes  No
    Your message goes here
    Are you sure you want to  Yes  No
    Your message goes here
  • Your opinions matter! get paid BIG $$$ for them! START NOW!!.. ➤➤
    Are you sure you want to  Yes  No
    Your message goes here
  • I went from getting $3 surveys to $500 surveys every day!! learn more... ●●●
    Are you sure you want to  Yes  No
    Your message goes here

Information Ethics

  1. 1. Information Ethics Chapter 4
  2. 2. Laws & Ethics
  3. 3. <ul><li>Ethical issues in the areas of copyright infringement and intellectual property rights are consuming the e-business world </li></ul><ul><li>Technology makes it extremely easy to copy everything digital! </li></ul>Ethics in the Information Age
  4. 4. As a result, several technology-related issues arise! Intellectual Property Intangible creative work that is embodied in physical form Copyright The legal protection afforded an expression of an idea Fair Use Doctrine In certain situations, its legal to use copyrighted material Pirated Software Unauthorized use, duplication, distribution, or sale of copyrighted software Counterfeit Software Software that is manufactured to look like the real thing and sold as such
  5. 5. <ul><li>The protection of consumer personal information over the Internet is getting an increasing amount of attention as consumers become more aware of the many online threats that exist to their personal information and businesses attempt to find ways to retain their customers trust (Peslak, 2005). </li></ul><ul><li>Two areas of threats </li></ul><ul><li>Outside threats </li></ul><ul><ul><ul><li>Hackers </li></ul></ul></ul><ul><ul><ul><li>Phishing schemes </li></ul></ul></ul><ul><li>Inside threats </li></ul><ul><ul><ul><li>Unintended use of consumer PI </li></ul></ul></ul><ul><ul><ul><li>PI sale to third parties </li></ul></ul></ul>Privacy Protection
  6. 6. <ul><li>Is the right to be left alone when you want to be, have control over your own personal possessions, and not to be observed without your consent. </li></ul><ul><li>Hmmm…… what about the use of cookies then? </li></ul>Privacy
  7. 7. <ul><li>Trust between companies, customers, partners, and suppliers is the support structure of e-business </li></ul><ul><li>Privacy continues to be a barrier to the growth of e-business </li></ul><ul><li>The unintentional use of consumer information and the resulting uncertainty of where consumer information ultimately end up diminishes consumer trust of e-commerce websites. </li></ul><ul><li>When consumers feel that they cannot trust how their personal information is going to be used by online businesses consumers simply choose not to shop online. </li></ul>Trust
  8. 8. <ul><li>Initially, e-businesses reported that they collected large amounts of consumer personal information for the purposes of; </li></ul><ul><ul><ul><li>improving services </li></ul></ul></ul><ul><ul><ul><li>and personalizing the customer’s experience while visiting their website. </li></ul></ul></ul><ul><li>Today more and more frequently, e-businesses are using PI for uses other than what it is originally authorized to do! </li></ul>E-business practices & Consumer Mistrust
  9. 9. <ul><li>Book discusses Saab public relations fiasco when a marketing firm “bent” the opt-in rules governing the use of email promotions. </li></ul><ul><li>In 2005, a survey of large and small businesses found that private smaller companies often placed marketing causes ahead of the altruistic motivation of protecting their customers (Peslak, A.R., 2005) </li></ul>Reason for Misuse
  10. 10. Consumer Protection <ul><li>Information has no ethics. Information does not care how it is used. It will not stop itself from spamming customers, sharing itself (sensitive or not), or revealing details to third parties, information cannot delete or restore itself </li></ul><ul><li>Therefore it is the responsibility of those who own or manage information to develop ethical use policies / guidelines </li></ul>
  11. 11. <ul><li>Laws were developed to ensure that consumer personal information is being handled securely and that the right to privacy is being enforced. </li></ul><ul><li>Examples of these laws include; </li></ul><ul><li>the Health Insurance Portability and Accountability Act (HIPAA), </li></ul><ul><li>the Family Education Rights and Privacy Act (FERPA), </li></ul><ul><li>Electronic Communications Privacy Act, </li></ul><ul><li>Sarbanes-Oxley Act, and the CAN-Spam Act </li></ul>Established Information related laws
  12. 12. <ul><li>In addition to these examples, the Federal Trade Commission developed five fair information practices for companies to follow that have Internet sites as part of their business. These five principles are listed on the next slide; </li></ul>Federal Trade Commission
  13. 13. <ul><li>Data collectors must disclose to consumers their information practices as it relates to the collection of personal information </li></ul><ul><li>Consumers must be given the options with respect to whether and how personal information collected from them may be used for purposes beyond those for which the information was provided </li></ul><ul><li>Consumers should be able to view and contest the accuracy and completeness of data collected about them </li></ul><ul><li>4. Data collectors must take reasonable steps to assure that information collected from consumers is accurate and secure from unauthorized use </li></ul><ul><li>5. A reliable mechanism must be used to impose sanctions for noncompliance with these fair information practices as a critical ingredient in any governmental or self-regulating program to ensure privacy online </li></ul>FTC Five Fair Information Practices
  14. 14. Information Management Policies <ul><li>Sensitive corporate information is a valuable resource </li></ul><ul><li>Management needs to develop a culture that is based on ethical principles that they can easily implement and employees can understand </li></ul><ul><li>Establishing this culture is based in the development of written policies that will guide personnel procedures and set organizational rules for the use of information </li></ul>
  15. 15. ePolicies <ul><li>Organizational practices & standards related to information </li></ul><ul><li>Protection from misuse of computer systems and IT resources </li></ul><ul><li>Minimally, Organizations should develop ePolicies . </li></ul><ul><li>ePolicies: are policies and procedures that address the ethical use of computers and Internet usage in the business environment </li></ul>
  16. 16. ePolicy types <ul><ul><ul><ul><ul><li>Ethical computer use policy </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>Information privacy policy </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>Acceptable use policy </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>E-mail privacy </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>Internet use policy </li></ul></ul></ul></ul></ul><ul><ul><ul><ul><ul><li>Anti-spam policy </li></ul></ul></ul></ul></ul>
  17. 17. Ethical computer use Guide computer use behavior; don’t play games at work; Policy should be clear on what happens after several infractions Information Privacy Policy Includes components related to adoption & Implementation, notice and disclosure, choice & consent, Information security, and information quality and access Acceptable Use Policy <ul><li>Users must agree to follow in order to have access to a network or the Internet. </li></ul><ul><ul><li>AUPs are common for most business and educational facilities </li></ul></ul>
  18. 18. Email at Work…Private? Email in the workplace is not Private! This means that any email sent over your companies LAN and processed through a company owned computers is subject to monitoring…. This also includes emails through web-based email accounts such as Yahoo!, Gmail, etc… All Iming is also subject to monitoring Email Privacy Policy Details the extent to which email messages may be read by others
  19. 19. More policies <ul><li>Internet Use Policy: contains general principles to guide the proper use of the Internet at work; this limits access to certain categories of websites, why the Internet is available to employees (and why it is not!) </li></ul><ul><li>Anti-Spam Policy: employees can not send unsolicited emails. </li></ul><ul><li>Spam by estimates accounts for 40-60% of most organizations email traffic </li></ul><ul><li>Spam clog e-mail systems and siphons IT resources away from legitimate business projects </li></ul>
  20. 20. Monitoring in the Workplace <ul><li>Employees shop online at work and email/IM friends and family from work…. </li></ul><ul><li>Employees consume portions of their work day surfing the web….. </li></ul><ul><li>As a result of this behavior….. </li></ul><ul><li>Employers are taken a “big brother” approach and monitoring employee Internet usage and emails. </li></ul>
  21. 21. Information Technology Monitoring <ul><li>Tracks employees activities using measures such as; </li></ul><ul><ul><li>Number of keystrokes </li></ul></ul><ul><ul><li>Error rates </li></ul></ul><ul><ul><li>And # of transactions processed </li></ul></ul>Key loggers / hardware key loggers Record keystrokes and mouse clicks Web Log Consists of one line of information for every visitor to a website
  22. 22. Employee Monitoring Policies <ul><li>The best path for an organization planning to engage in employee monitoring is open communication surrounding the issue </li></ul><ul><li>CSO’s that are open about how, when, and where they monitor employees will find that employees police themselves </li></ul>
  23. 23. <ul><li>Organizational information is intellectual capital </li></ul><ul><li>Just like protecting Money in a bank and providing a safe environment for employees, organizations must also protect their intellectual capital </li></ul>Intellectual Capital
  24. 24. <ul><li>Information Security is a broad term encompassing the protection of information from accidental or intentional misuse by persons inside or outside the organization </li></ul><ul><li>Security is the most fundamental & critical of all technologies/ disciplines an organization must have squarely in place to execute its business strategy </li></ul>Information Security
  25. 25. Types of Attacks <ul><li>Phishing Attacks </li></ul><ul><li>Socially engineered attempts to gain access to credentials or other information valuable to the attacker </li></ul><ul><li>Man-in-the-Middle Attacks </li></ul><ul><li>A man-in-the-Middle (MITM) attack also known as TCP hijacking, occurs when an attacker sniffs packets from the network, modifies them, and then inserts them back into the network </li></ul><ul><li>MITM attack to obtain a user’s credential such as passwords, usernames, or user ID’s. </li></ul><ul><li>Once the MITM hijack has occurred, the attacker also has the ability to eavesdrop on communications, change, delete, reroute, add, and divert the intercepted data </li></ul>
  26. 26. <ul><li>Organizations make information available to employees, customers, and partners electronically </li></ul><ul><li>Doing business electronically automatically creates tremendous information security risks for organizations </li></ul><ul><li>As we have discussed before, most information security issues are not a technical issue but rather a people issue </li></ul><ul><li>CSI/FBI Computer Crime and Security survey reported that 38% of respondents indicated security incidences originated within the enterprise </li></ul>Defending Information Systems
  27. 27. People: The First Line of Defense <ul><li>Insiders: are people that are legitimate users who purposely or accidentally misuse their access to the business environment and cause some kind of business-affecting incident </li></ul><ul><li>To protect against security breaches internally, organizations need to develop PW policies, and implement plans that create checks and balances that limit the risk of social engineering attacks </li></ul>
  28. 28. Information Security Policy & Security Plans <ul><li>Information Security Policy: identify rules required to maintain information security </li></ul><ul><li>Security Plans: details how information security policy will be implemented. </li></ul><ul><li>Cover such things as; </li></ul>
  29. 29. Security Plans <ul><ul><li>Ensure security & confidentiality of protected info </li></ul></ul><ul><li>Protect against anticipated threats or hazards to security or integrity of info </li></ul><ul><li>Protect against unauthorized access to or use of Protected info that could result in substantial harm or inconvenience to any customer </li></ul><ul><li>Meeting these criteria also ensures that organizations are in compliance with the Gramm-Leach Bliley Act </li></ul>Incident Response Plans and Disaster Recovery Plans are included in Security planning
  30. 30. Security Planning in Practice <ul><li>Organizations typically use IS security professionals to conduct threat assessments and risk analyses that are specific to that organizations needs. These site security evaluations often include; </li></ul><ul><ul><li>identifying organizational assets, </li></ul></ul><ul><ul><li>identifying relevant threats </li></ul></ul><ul><ul><li>comparing the expected costs that the threat would cause the organization against the costs associated with protecting the organization against such threats. </li></ul></ul><ul><li>This process of evaluating organizations information systems and technology security works but leaves the issue of information assurance as an afterthought in the information system development process </li></ul>