Ethics in Information Technology, Fifth Edition 9781285197159
Chapter 3
Computer and Internet Crime
Self-Assessment Questions
1. (b.) malware infection
Discussion Questions
1. Develop a strong argument against the adoption of a bring your own device (BYOD) policy
for a large financial services organization. Now develop a strong argument in favor of adop
tion of such a policy.
2. A successful distributed denial-service attack requires the downloading of software that turns
unprotected computers into zombies under the control of the malicious hacker. Should the
owners of the zombie computers be fined or otherwise punished as a means of encouraging
people to better safeguard their computers? Why or why not?
3. Provide a real example or describe a hypothetical situation where a legitimate organization
used spam in an effective and nonintrusive manner to promote a product or service.
4. Some IT security personnel believe that their organizations should employ former com
puter criminals to identify weaknesses in their organizations’ security defenses. Do you
agree? Why or why not?
5. You have been assigned to be a computer security trainer for your firm’s 2,000 employees
and contract workers. What are the key topics you would cover in your initial one-hour basic
training program for non-IT personnel? What kind of additional security-related training
might be appropriate once people have the basics covered?
6. Your computer science instructor has assigned a semester-long project to develop a zeroday
exploit for the Windows 8 operating system. Do you think this is an appropriate class
project? Why or why not?
7. How should a nonprofit charity handle the loss of personal data about its donors? Should law
enforcement be involved? Should donors be informed?
8. Draft a legitimate-looking phishing email that would strongly tempt its recipients to click on
a link to a Web site or open an email attachment.
9. What is the difference between industrial spying and the gathering of competitive intelli
gence? Is the use of competitive intelligence ethical or unethical? Why?
10. How would you distinguish between a hacktivist and a cyberterrorist? Should the use of
hacktivists by a country against enemy organizations be considered an act of war? Why or
why not? How about the use of cyberterrorists?
11. Outline action steps necessary to implement trustworthy computing.
12. What is the difference between risk assessment and an IT security audit?
What Would You Do?
1. Students’ answers will vary. First they should understand what the position would require them to
do, without making any assumptions. At this stage they would need to gather details regarding the
2. Students’ answers will vary. They could stall the blackmailer by agreeing to pay, and requesting
3. Students’ answers will vary. They should be aware of the risks as well as the possible benefits in
5. Students’ answers will vary. They should begin by understanding their corporate security policy. It
6. Students’ answers will vary. The general consensus seems to be that the Controlling the Assault of
8. Students’ answers will vary. Even though the probability of the problem being discovered is low,
Cases
Case 1: Defending Against Distributed Denial-of-Service Attacks
1. Students’ answers may vary. DDoS mitigation service organizations monitor clients’ network
2. The three potential DDoS attackers of an e-commerce company are as follows:
Case 2: Anonymous and Social Hacktivism
2. Students’ answers may vary. Some of them may say that they believe that Anonymous’ actions to
Case 3: Computer Forensics
1. In the case of the New York subway bomber, computer forensic investigators with the FBI found