3-1
Ethics in Information Technology, Sixth Edition
Ethics in Information Technology, Sixth Edition
Chapter 3
Cyberattacks and Cybersecurity
Self-Assessment Questions
1. c. about 58 percent
2. True
3. d. exploit
13. a. Entering a user name and a strong end-user password at least 10 characters long including
capital letters, numbers, and special characters
14. d. next-generation firewall
Discussion Questions
1. Imagine that you are designing a smishing scam that involves sending texts to people to entice
them to go to a website and provide personal information that you can use to access their
checking account. Craft a text message that would be difficult for people to ignore. Design a
simple web page that would look legitimate to people who bank at your bank and that would
capture their checking account number and PIN.
Students’ answers will vary. They can refer to Figure 3-3 for ideas on things to include in the email.
3-2
Ethics in Information Technology, Sixth Edition
Students might suggest any of the following: in both the email and web page, use the actual logo of
2. A successful DDoS attack requires the downloading of software that turns unprotected
computers into zombies under the control of the malicious hacker. Should the owners of the
zombie computers be tracked down, identified, and fined or otherwise punished as a means of
encouraging people to better safeguard their computers? Why or why not?
Student’s answers will vary. Everyone should adhere to a basic level of security, but at the same
time, everyone cannot be expected to possess the knowledge of IT professionals or hackers.
3. Briefly describe the difference between a risk assessment and an IT security audit?
Risk assessment is the process of assessing security-related risks to an organization’s computers
and networks from both internal and external threats that could prevent an organization from
4. Identify and briefly discuss a real-world example of a legitimate organization using spam in
an effective and nonintrusive manner to promote a product or service.
Students’ answers will vary depending on their experience and also on their personal views about
3-3
Ethics in Information Technology, Sixth Edition
5. Briefly describe the difference between reasonable assurance and risk assessment.
The concept of reasonable assurance in connection with IT security recognizes that managers must
use their judgment to ensure that the cost of control does not exceed the system’s benefits or the
6. Some IT security personnel believe that their organizations should employ former computer
criminals who now claim to be white hat hackers to identify weaknesses in their
organizations’ security defenses. Do you agree? Why or why not?
Students’ answers will vary. On paper, this may sound like the perfect solution. After all, who
would be better qualified to identify weaknesses in an organization’s security defenses than
7. The National Security Agency (NSA) works to detect and prevent threats to National Security
Systems, which includes systems that handle classified information or are otherwise critical to
military or intelligence activities. The NSA plays a vital role in our national security by
providing America’s leaders with critical information they need to defend our country, save
lives, and advance U.S. goals and alliances globally. Tailored Access Operations (TAO) is a
group of super hackers within the NSA that collects intelligence about foreign targets by
breaking into their computers, stealing data, and monitoring communications. TAO is also
responsible for developing programs that could destroy or damage foreign computers and
networks via cyberattacks if commanded to do so by the president. What sort of personal
characteristics would be important in selecting a candidate for the NSA super-secret Tailored
Access Operations organization? What would be some of the pros and cons of such a
position? Would you consider taking such a position? Why or why not?
Student’s answers will vary. Students might suggest that candidates for such a position would need
to be: highly skilled in some aspect of computer science, especially cybersecurity; willing to
3-4
Ethics in Information Technology, Sixth Edition
8. Hundreds of a bank’s customers have called the customer service call center to complain that
they are receiving text messages on their phone telling them to access a website and enter
personal information to resolve an issue with their account. What action should the bank
take?
Students’ answers will vary. Suggested actions could include: quickly alerting all of its customer
9. How would you distinguish between a hacktivist and a cyberterrorist? Should the use of
hacktivists by a country against enemy organizations be considered an act of war? Why or
why not? How about the use of cyberterrorists?
Students’ answers will vary. Hacktivism, a combination of the words hacking and activism, is
What Would You Do?
1. Students’ answers will vary. Students will likely propose conducting a risk assessment to assess
security-related risks to the retailers computers and networks from both internal and external
threats. The risk assessment should identify critical IT assets, identify risks or threats (including
threats from malicious or careless employees), assess the likelihood and impact of each potential
3-5
Ethics in Information Technology, Sixth Edition
2. Students’ answers will vary. Students should suggest immediately alerting all staff about the spear
phishing emails and explaining that if anyone has actually clicked on the link and given the
3. Students’ answers will vary. Students might suggest trying to stall the blackmailer by agreeing to
pay, and requesting time, while their security experts attempt to fix the vulnerability. However,
students should recognize that there is often no good option in these types of situations. While some
4. Students’ answers will vary. A blended threat is a sophisticated and potentially damaging type of
cyberattack. Some students could suggest ignoring the threat because it might simply be a baseless
5. Students’ answers will vary. First, they should understand what the position would require them to
do. This would require that they spend considerable time and effort gathering details about the
6. Students’ answers will vary, but should include:
Information about exploits
3-6
Ethics in Information Technology, Sixth Edition
Cases
Case 1: Fairplay Turns to a Managed Security Service Provider
1. Students’ answers may vary. Students may point out that using an MSSP can allow a small retailer
such as Fairplay to gain access to a high level of cybersecurity, networking, and systems-
management expertise. Smaller companies often cannot afford to maintain enough experienced in-
2. Students’ answers may vary. Students might suggest that the first step the management team should
take is to carefully evaluate ControlScan’s PCI gap analysis along with its accompanying set of
recommendations. After determining which recommendations it will follow, the management
3. Students’ answers may vary depending on their research. Their answers might include technical
details as well as information regarding the new fines faced by merchants that were not PCI 3.0
Case 2: Sony’s Response to North Korea’s Cyberattack
1. Students’ answers will vary. Some students may be sympathetic to the position in which Sony
found itself, and point out that the company was, in fact, the victim of a crime. Students might
3-7
Ethics in Information Technology, Sixth Edition
2. Students’ answers will vary. Some students will likely point to weaknesses in Sony’s security
systems and suggest that the first thing Sony could have done differently would have been to have
3. Students’ answers will vary. Many students will likely believe that the U.S. government has an
important role to play in preventing real-world violence and cyberattacks. However, students may
disagree regarding which tools and tactics are appropriate and acceptable for the government to use