This chapter discusses legal, ethical, and professional issues related to information security. It differentiates between laws, which mandate or prohibit behaviors and carry sanctions, and ethics, which define socially acceptable behaviors. The chapter outlines several important US laws regarding privacy, copyright, computer crimes, and financial reporting. It also discusses organizational liability and the need for security policies and due care or due diligence to protect systems and data.