Introduction
The case of publicly traded company TechFite reveals a substantial number of ethically questionable activities being committed by the company’s Applications Divisions. Not only are their accusations of theft of proprietary information but also evidence of conflicts of interest, dummy accounts used to gain escalation of privilege, and security omissions that cannot be justified. This paper will address the ethical issues for cybersecurity that relate to the case of TechFite, discuss ethically questionable behaviors and omissions of people who fostered the unethical atmosphere, and examine ways to mitigate problems and enhance security awareness at the company.
Ethical Issues for Cybersecurity
When it comes to establishing ethical guidelines in cybersecurity, the main concerns focus on protecting data. Whether it is in health care, finance, or tech, data security has to be the number one issue—and that means confidentiality, integrity and access all have to be secured, according to the Information Systems Security Association International (ISSA, 2018). In the case of TechFite, a number of ethical issues have cropped up with regards to confidentiality, integrity and access. Before examining them, however, it is helpful to examine the guidelines one by one.
Ethical Guidelines
Privacy is the basic umbrella ethical issue that governs most ethical guidelines in information security (Shinder, 2005). All clients have a reasonable expectation to privacy with respect to their proprietary information. That is the reason clients sign non-disclosure agreements. Protecting information, therefore, is a key ethical responsibility in information security. Keeping client information segregated is important—for example, by using a Chinese wall. Limiting administrative rights within the department and allowing access to only be granted by using certain computers where activity can be monitored is another guideline that should be standard throughout the industry (GIAC, 2018).
Justification and Examples
The reason that privacy serves as the underlying foundation of all ethical guidelines related to information security is that the very essence of information security is rooted in the concept of keeping information out of the hands of people who should not have access to it. The digital age has allowed for information flows to be made possible in ways that are easier today than ever before; however, that ease comes with a price, which is the risk of information flows being hacked. The guiding ethical principle in IS is that information should be protected so that it is shared only with those who have permission to see it. An example of this can be seen in the health care industry, where patients’ rights are affirmed in HIPAA law, which stipulates that all patient information must be protected by health care facilities that store it digitally. When Anthem Blue Cross had 78 million patient records hacked, it was a major disaster that showed just how important the fundamental ethical principle of privacy is in the field of Information Security (Lord, 2018).
Within the field, there are certain guidelines that should be followed as well—such as protecting proprietary information, using basic security systems like Chinese walls, and so on. As Brewer and Nash (1989) point out, “it should be noted that in the United Kingdom the Chinese Wall requirements of the UK Stock Exchange have the authority of law and thus represent a mandatory security policy whether implemented by manual or automated means” (p. 206). In other words, these basic guidelines are actually recognized as laws in many parts of the world where ethical practice in IS is virtually mandated by government.
Behaviors and Omissions
The behaviors and omissions of behaviors at TechFite that fostered the unethical practices were numerous in the case study. IT Security Analyst Nadia Johnson was one of the main culprits, but not the only one. Johnson showed that when it came to protecting the company against external threats, the firm had done well. However, the problem of documentation of internal threats was an issue. In short, there was no documentation. External threats were mitigated. Internal threats were quite another story, and there were far too many omissions and behaviors permitted by Johnson to believe that, ethically speaking, the Applications Division was in a healthy state. There was zero description of whether accounts had been audited, whether...
References
Brewer, D. F., & Nash, M. J. (1989, May). The Chinese wall security policy. In Proceedings. 1989 IEEE Symposium on Security and Privacy (pp. 206-214). IEEE.
GIAC. (2018). Code of ethics. Retrieved from https://www.giac.org/about/ethics
ISSA. (2018). Code of ethics. Retrieved from https://www.issa.org/page/CodeofEthics
Lord, N. (2018). Top 10 Biggest Healthcare Data Breaches of All Time. Retrieved from https://digitalguardian.com/blog/top-10-biggest-healthcare-data-breaches-all-time
Patrick, N. (2018). 9 signs your security awareness training is failing. Retrieved from https://peoplesec.org/category/security-awareness-training-and-education-sate/
Shinder, D. (2005). Ethical issues for IT security professionals. Retrieved from https://www.computerworld.com/article/2557944/ethical-issues-for-it-security-professionals.html
Future of Cyber Security Report on the Legal and Technical Future of Cyber Security The future of Cyber security relies on the quality of decisions that the government seconded by the private sector process as for now. Attacks on networks and databases have become a complex and lucrative activity that attracts a financial gain for people involved in that business. For this reason, there is a need to determine whether the existing
TechFite Case Study: Ethical Issues and Mitigation Strategies in CybersecurityA. Ethical Issues for Cybersecurity1. Ethical Guidelines and Standards for Information SecurityIn the TechFite case, multiple ethical guidelines and standards concerning information security were breached. Organizations, especially TechFite, which deal with sensitive client data, must adhere to established procedures such as the (ISC)� Code of Ethics and the International Organization for Standardization (ISO) 27001. These frameworks emphasize confidentiality, integrity, availability of
Social Networks and Computer Ethics For the past 20 years, there have been many changes caused by the internet on many aspects of the contemporary life. The internet is growing rapidly. As of 2006, it was recorded that the number of internet users was about four million. For a long time, there have been promises made on how internet changes will positively impact people worldwide. These promises have reached many people
Physical Security in Public AreasAbstract/SummaryThis paper examines the effectiveness of physical security measures in public areas, by looking at spaces such as schools, airports, stadiums, and malls. It discusses current strategies, including surveillance cameras, metal detectors, and access control systems. It also examines the need customized approaches since all spaces are different. Schools require security that balances safety with an open, welcoming environment, whereas airports can use stricter, more invasive
Essentially, securing the electronic frontier is very critical because of the potential harms that cyber crime and fraud cause to individual, businesses and nations as a whole. One of the effective strategies that could be employed to secure the electronic frontier is the collaboration of the government with the private and public organizations. Increasing number of governments has implemented method to secure the electronic frontier without success. Since corporate organizations
Cyber Crime Cybercrime has been a hot button topic in recent years. A crime involving digital services or computers, cybercrimes typically is when someone targets a computer for a crime, uses a computer as a tool for a crime, or has computer containing evidence of a crime. Since the rise of information technology, cybercrime has become taken center stage as a shift in criminal activity means more criminals doing business online
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now