3-3
Ethics in Information Technology, Sixth Edition
5. Briefly describe the difference between reasonable assurance and risk assessment.
The concept of reasonable assurance in connection with IT security recognizes that managers must
use their judgment to ensure that the cost of control does not exceed the system’s benefits or the
6. Some IT security personnel believe that their organizations should employ former computer
criminals who now claim to be white hat hackers to identify weaknesses in their
organizations’ security defenses. Do you agree? Why or why not?
Students’ answers will vary. On paper, this may sound like the perfect solution. After all, who
would be better qualified to identify weaknesses in an organization’s security defenses than
7. The National Security Agency (NSA) works to detect and prevent threats to National Security
Systems, which includes systems that handle classified information or are otherwise critical to
military or intelligence activities. The NSA plays a vital role in our national security by
providing America’s leaders with critical information they need to defend our country, save
lives, and advance U.S. goals and alliances globally. Tailored Access Operations (TAO) is a
group of super hackers within the NSA that collects intelligence about foreign targets by
breaking into their computers, stealing data, and monitoring communications. TAO is also
responsible for developing programs that could destroy or damage foreign computers and
networks via cyberattacks if commanded to do so by the president. What sort of personal
characteristics would be important in selecting a candidate for the NSA super-secret Tailored
Access Operations organization? What would be some of the pros and cons of such a
position? Would you consider taking such a position? Why or why not?
Student’s answers will vary. Students might suggest that candidates for such a position would need
to be: highly skilled in some aspect of computer science, especially cybersecurity; willing to