3-1
Ethics in Information Technology, Sixth Edition
Chapter 3
Cyberattacks and Cybersecurity
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Lecture Notes
Overview
Chapter 3, “Cyberattacks and Cybersecurity,” describes the types of ethical decisions that IT
professionals must make, as well as the business needs they must balance when dealing with
security issues. The chapter identifies the most common computer-related security incidents and
provides numerous reasons why such incidents are increasing. This chapter includes information
3-2
Ethics in Information Technology, Sixth Edition
Objectives
As students read this chapter, they should consider the following questions:
Why are computer incidents so prevalent, and what are their effects?
What can be done to implement a strong security program to prevent cyberattacks?
What actions must be taken in the event of a successful security intrusion?
Teaching Tips
Organizations Behaving Badly
1. Introduce the term zero-day exploita cyberattack that takes place before the security
I. The Threat Landscape
1. Begin this section by discussing the importance of safeguarding confidential business data
2. Use the examples on pages 85-86 to explain some of the measures that organizations are
A. Why Computer Incidents Are So Prevalent
1. Explain that increasing computing complexity, expanding and changing systems, an increase
in the prevalence of bring your own device (BYOD) policies, a growing reliance on software
Increasing Complexity Increases Vulnerability
1. Note that computing environments have become enormously complex. Cloud computing,
3-3
Ethics in Information Technology, Sixth Edition
2. Explain that the number of possible entry points to a network expands continually as more
devices are added, increasing the possibility of security breaches.
Expanding and Changing Systems Introduce New Risks
1. An important point to make is that it is increasingly difficult for IT organizations to keep up
Increasing Prevalence of BYOD Policies
1. Introduce the term bring your own device (BYOD)a business policy that permits, and in
2. Explain that this practice raises many potential security issues.
Growing Reliance on Commercial Software with Known Vulnerabilities
1. Introduce the term exploit, and explain that software developers create and issue a “fix,” or
patch, to eliminate a security problem once it is discovered. Note how important it is for
Increasing Sophistication of Those Who Would Do Harm
1. Explain that today’s computer menace is much better organized and may be part of an
organized group (for example, Anonymous, Chaos Computer Club, Lizard Squad,
B. Types of Exploits
1. Use this section to discuss some of the more common attacks, including ransomware, viruses,
3-4
Ethics in Information Technology, Sixth Edition
2. Note that some of these exploits are increasingly being aimed at smartphones.
Ransomware
1. Introduce the term ransomwaremalware that stops you from using your computer or
accessing your data until you meet certain demands, such as paying a ransom or sending
Viruses
1. Technically, a virus is a piece of programming code, usually disguised as something else,
that causes a computer to behave in an unexpected and usually undesirable manner.
2. Point out that almost all viruses are attached to a file, meaning the virus executes only when
Worms
1. Discuss the differences between worms and viruses.
2. Note that the negative impact of a worm attack on an organization’s computers can be
Trojan Horses
1. Point out that a Trojan horse can be delivered via an email attachment, downloaded from a
website, or contracted via a removable media device such as a DVD or USB memory stick.
2. Note that the Department of Homeland Security (DHS) officials say they have evidence that
Students interested in learning more about viruses and antivirus software in
3-5
Ethics in Information Technology, Sixth Edition
3. Introduce the term logic bomb.
Blended Threat
Spam
1. Introduce the term spamthe use of email systems to send unsolicited email to large
numbers of people. Explain that most spam is a form of low-cost commercial advertising,
2. Note that the cost of creating an email campaign for a product or service can be several
3. Spam forces unwanted and often objectionable material into email boxes, detracts from the
4. Point out that spam is also often used to entice unsuspecting recipients to take actions that
result in malware being downloaded to the computer.
5. Introduce the Controlling the Assault of Non-Solicited Pornography and Marketing
(CAN-SPAM) Act which went into effect in January 2004.
Distributed Denial-of-Service (DDoS) Attacks
1. Point out that a distributed denial-of-service (DDoS) attack does not involve infiltration of
the targeted system. Instead, it keeps the target so busy responding to a stream of automated
3-6
Ethics in Information Technology, Sixth Edition
Rootkits
1. Introduce the class to rootkits, noting that once installed, a rootkit can be used by an attacker
to gain full control of the system and even obscure the presence of the rootkit from legitimate
Advanced Persistent Threat
1. Introduce the term advanced persistent threat (APT)a network attack in which an
intruder gains access to a network and stays thereundetectedwith the intention of
Phishing
1. Introduce phishingthe act of fraudulently using email to try to get the recipient to reveal
Smishing and Vishing
1. Discuss the difference between smishing and vishing. Use examples to aid the discussion.
Cyberespionage
1. Introduce the term cyberespionage the deployment of malware that secretly steals data in
2. Note that the type of data most frequently targeted in a cyberespionage attack includes data
Cyberterrorism
1. Introduce the term cyberterrorismthe intimidation of government or civilian population
3-7
Ethics in Information Technology, Sixth Edition
energy, transportation, financial, law enforcement, and emergency response) to achieve
political, religious, or ideological goals.
2. Explain that the Department of Homeland Security (DHS) is large federal agency whose
goal is to provide a “safer, more secure America, which is resilient against terrorism and
Quick Quiz 1
1. (True or False) An organization can lower its risk of security-related incidents by enacting a
BYOD policy.
2. _____ is malware that stops you from using your computer or accessing your data until you
meet certain demands, such as paying the attacker a specified amount of money.
3. A(n) _____ is one in which a malicious hacker takes over computers via the Internet and
causes them to flood a target site with demands for data and other small tasks.
4. _____ is the act of fraudulently using email to try to get the recipient to reveal personal
data.
5. _____ involves the deployment of malware that secretly steals data in the computer systems
of organizations, such as government agencies, military contractors, political organizations,
and manufacturing firms.
3-8
Ethics in Information Technology, Sixth Edition
C. Federal Laws for Prosecuting Computer Attacks
1. Over the years, several laws have been enacted to help prosecute those responsible for
Critical Thinking Exercise: Hiring a Black Hat Hacker
1. Reasons to hire the individual could include: the hacker has the technical skills to do a
thorough review of the company’s software products, which could potentially be shared with
2. By definition, however, a black hat hacker is someone who has engaged in activities that
violate computer or Internet security maliciously or for illegal personal gain. The reasons not
to hire such a person are many, including the real possibility that the hacker would use the
II. The CIA Security Triad
1. Introduce the term CIA security triadconfidentiality, integrity, and availability.
2. Confidentiality ensures that only those individuals with the proper authority can access
sensitive data such as employee personal data, customer and product sales data, and new
product and advertising plans.
3. Integrity ensures that data can only be changed by authorized individuals so that the
A. Implementing CIA at the Organization Level
1. Explain that implementing CIA begins at the organization level with the definition of an
overall security strategy, performance of a risk assessment, laying out plans for disaster
3-9
Ethics in Information Technology, Sixth Edition
recovery, setting security policies, conducting security audits, ensuring regulatory standards
compliance, and creating a security dashboard. Security Strategy
1. Note that implementing CIA security at the organization level requires a risk-based security
Risk Assessment
1. Introduce the term risk assessment. The goal of risk assessment is to identify which
2. In the context of an IT risk assessment, an asset is any hardware, software, information
3. Introduce the term reasonable assurance.
5. Use Table 3-3 to aid a discussion of what a risk assessment might look like for an
Disaster Recovery
1. Data availability requires implementing products, services, policies, and procedures that
ensure that data are accessible even during disaster recovery operations.
Security Policies
1. Introduce the term security policy.
Ask students to read and then discuss the following article:
3-10
Ethics in Information Technology, Sixth Edition
2. Explain that a good security policy delineates responsibilities and the behavior expected of
3. Experienced IT managers understand that users will often attempt to circumvent security
4. Note that system administrators must also be vigilant about changing the default usernames
and passwords for specific devices when they are added to an organization’s network.
5. An area of growing concern for security experts is the use of wireless devices to access
Security Audits
1. Introduce the term security audit.
2. A security audit should test how well policies are being implemented. It should also review
who has access to particular systems and data and what level of authority each user has. A
Regulatory Standards Compliance
1. Use Table 3-4 to aid a discussion of some of the types of additional standards and regulations
Security Dashboard
1. Note that many organizations use security dashboard software to provide a comprehensive
display of all key performance indicators related to an organization’s security defenses,
Quick Quiz 2
1. The CIA security triad includes confidentiality, integrity, and _____.
Teaching
Tip
Direct students to the SANS Institute’s website to review some of the security
related policy templates offered by that organization (www.sans.org/security-
resources/policies).
3-11
Ethics in Information Technology, Sixth Edition
2. The concept of _____ recognizes that managers must use their judgment to ensure that the
cost of control does not exceed the system’s benefits or the risks involved.
3. A(n) _____ is one that is pivotal to continued operations and goal attainment.
4. A(n) _____ defines an organization’s security requirements, as well as the controls and
sanctions needed to meet those requirements.
5. A (n) _____ evaluates whether an organization has a well-considered security policy in place
and if it is being followed.
B. Implementing CIA at the Network Level
1. Note that the Internet provides a wide-open and well-travelled pathway for anyone in the
2. Organizations must carefully manage the security of their networks and implement strong
Authentication Methods
1. Explain that to maintain a secure network, an organization must authenticate users attempting
2. A number of multifactor authentication schemes can be used, such as biometrics, one-time
Firewall
1. Introduce the term firewall.