Management of Information Security, Fourth Edition 12-1
Chapter 12
Law and Ethics
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 12-2
Lecture Notes
Overview
In this final chapter, students will learn about the application of laws and ethics to the
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Differentiate between law and ethics
Teaching Tips
Introduction
1. Emphasize that to avoid liability, the information security practitioner must understand
Law and Ethics in InfoSec
1. Discuss laws and their relationship to ethics, noting that laws are largely drawn from
are fixed moral attitudes or customs of a societal group.
InfoSec and the Law
1. Educate students on the need for InfoSec professionals and managers to have a
Types of Law
1. Explain that civil law covers laws pertaining to relationships between and among
actively enforced and prosecuted by the state.
Management of Information Security, Fourth Edition 12-3
3. Describe tort law as a subset of civil law that allows individuals to seek redress in the
event of personal, physical, or financial injury.
4. Provide students with an understanding of private law, which regulations the
Relevant U.S. Laws
1. Explain that the United States has led the development and implementation of
information security legislation to prevent misuse and exploitation of information and
information technology.
2. Provide students with a list of U.S. federal laws relevant to information security, such
4. Note that the penalty under the CFA depends on the value of information obtained and
whether the offense is judged to been committed for one of the following reasons:
a. Purposes of commercial advantage
b. Private financial gain
c. In furtherance of a criminal act
5. Explain how the CFA Act was further modified by the USA PATRIOT Act of 2001,
7. Describe the Computer System Security and Privacy Advisory Board established by the
CSA as a board that identifies emerging managerial, technical, administrative, and
physical safety issues relative to computer systems security and privacy.
8. Note that the CSA amended the Federal Property and Administrative Services Act of
1949, requiring that the National Bureau of Standards distribute standards and
guidelines pertaining to federal computer systems.
9. Make students aware of the fact that one of the provisions within the CSA requires any
Management of Information Security, Fourth Edition 12-4
when necessary to provide service, or by customer request.
13. Describe the use of aggregate information, which is permitted under the law, and
mention the potential of violating privacy if it is cross-indexed with other types of
available information.
14. Explain how the Federal Privacy Act of 1974 regulates the government’s use of private
16. Discuss the Electronic Communications Privacy Act (ECPA) of 1986, and note that
they address the ability for Federal organizations to perform different types of wire
taps, and the circumstances under which the wire taps are legal.
17. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 should be
described as an act intended to protect the confidentiality and security of healthcare
data.
18. Note that the HIPAA act requires organizations that retain health care information to
of health information to the minimum required for health care services required.
20. List the five fundamental privacy principles of HIPAA:
a. Consumer control of medical information
21. Educate students on the American Recovery and Reinvestment Act (ARRA), which
was designed to provide tax cuts and funding for programs, federal contracts, grants,
and loans, in effort to respond to the economic crisis in the United States.
22. Describe how the Health Information Technology for Economic and Clinical Health
(HITECH) Act, which is part of the ARRA, grants the authority to impose civil money
penalties for violations of the HIPAA rules.
Management of Information Security, Fourth Edition 12-5
25. Explain how the Economic Espionage Act (EEA) of 1996 was designed to protect trade
secrets from foreign governments that might undermine American companies, as well
as protect trade secrets from American companies in general.
26. Describe the Security and Freedom through Encryption Act of 1997 as an act that
29. The Sarbanes-Oxley (SOX) Act of 2002 should be described as an outcome of the
Enron and WorldCom Financial scandals. Point out that it is designed to enforce
accountability for financial reporting and record-keeping at publicly traded
corporations.
30. Discuss the responsibilities of the CEO and CFO in complying with the Sarbanes-
32. Explain that the current version of the PCI DSS standard is 2.0, and list the three key
steps within the standard:
a. Assess
b. Remediate
c. Report
33. List the three sub-standards that are present within the PCI DSS:
34. Provide students a list of the six steps related to the requirements of the PCI DSS, and
provide examples of how each one is fulfilled:
35. Provide students with an overview of some of the information security related laws that
are currently moving through the U.S. Congress, such as the Data Security Act of 2010,
the Data Security and Breach Notification Act of 2010, and the Cybersecurity Act of
2012.
Management of Information Security, Fourth Edition 12-6
International Laws and Legal Bodies
1. Explain that organizations that do business on the Internet are doing business globally,
and that international trade is governed by international treaties and trade agreements.
agents involved in international crimes and extradition processes.
3. Discuss the Digital Millennium Copyright Act (DMCA), which is intended to reduce
the impact of copyright, trademark, and privacy infringement, especially due to the
removal of technological copyright protection measures. Make students aware of the
European Union and United Kingdom versions of the DMCA.
State and Local Regulations
1. Explain that there are various state and local regulations that affect the use of computer
technology.
2. Discuss the Georgia Computer Systems Protection Act of 1991, which contains various
computer security provisions and establishes penalties for using IT to attack or exploit
Policy versus Law
1. Describe how policies function similarly to laws, but note that ignorance of policy is a
viable defense. Provide students with some key elements of an effective policy, such as
a policy being uniformly enforced for all employees.
Quick Quiz 1
1. The ____________________ of 1986 is a collection of statutes that regulates the
interception of wire, electronic, and oral communications.
Management of Information Security, Fourth Edition 12-7
2. True or False: The Sarbanes-Oxley (SOX) Act of 2002 was passed as a result of the
Enron and WorldCom financial scandals.
3. All but which of the following is one of the five fundamental privacy principles of
HIPAA?
A. Public control of medical information
B. Boundaries on the use of medical information
C. Balance of public responsibility for the use of medical information
D. Security of health information
4. Which entity is not exempt from the Federal Privacy Act of 1974?
A. Bureau of the Census
B. U.S. Congress
C. Hospitals
D. Credit agencies
5. Which law, originally passed in 1986 and amended in 1996, contains provisions that
determine the penalties for computer related crimes?
A. PATRIOT Act
B. Computer Fraud and Abuse Act
C. Digital Millennium Copyright Act
D. Computer Security Act
Ethics in InfoSec
1. Discuss with students the importance of ethics knowledge in InfoSec, and provide
students with information on The Ten Commandments of Computer Ethics.
2. Educate students on the foundations and frameworks of ethics:
a. Normative ethics
3. Make students aware of the different ethical standards that result from the ethical
frameworks:
a. Utilitarian approach
b. Rights approach
Management of Information Security, Fourth Edition 12-8
Ethics and Education
1. Explain the importance of education in leveling the ethical perceptions in a small
population. Note that employees must be trained and kept up to date on information
Deterring Unethical and Illegal Behavior
1. Note that it is the responsibility of InfoSec personnel to deter unethical and illegal acts,
through the use of policy, education, training, and technology controls or safeguards.
2. Discuss the three general categories of unethical behavior that organizations and society
should seek to eliminate:
Professional Organizations and Their Codes of Ethics
1. Explain that a number of professional organizations have established codes of conduct
and/or codes of ethics that members are expected to follow.
Association for Computing Machinery (ACM)
1. Introduce the Association for Computing Machinery (ACM) as a professional society
that promotes education and requires members to conform to a code of ethics, which
Teaching
A more detailed breakdown of different types of ethical philosophies can be
Management of Information Security, Fourth Edition 12-9
International Information Systems Security Certification Consortium, Inc.
(ISC)2
1. Explain the (ISC)2 as a nonprofit organization that focuses on the development and
implementation of InfoSec certifications and credentials.
2. Educate students on the code of ethics put forth by the (ISC)2:
a. Protect society, the commonwealth, and the infrastructure
SANS
1. Discuss the System Administration, Networking, and Security Institute as a
professional research and education cooperative organization.
2. Make students aware of the different sections of SANS’s code of ethics, which an
Information Systems Audit and Control Association (ISACA)
1. Describe the ISACA as a professional association with a focus on auditing, control, and
Information Systems Security Association (ISSA)
1. Introduce the ISSA, which is a nonprofit society of information security professionals
Organizational Liability and the Need for Counsel
1. Define liability as legal obligation, which can be applied to conduct even when no law
or contract has been breached.
Management of Information Security, Fourth Edition 1210
3. Note that if an employee acting with or without authorization commits an illegal act or
unethical act, an organization may be liable for any damages. Point out that liability is
Key Law Enforcement Agencies
1. Note that local law enforcement is usually the first point of contact when an
organization needs assistance from law enforcement.
2. List some of the key federal agencies that are charged with the protection of U.S.
4. List some of the components of the DHS National Protection and Programs Directorate:
a. Federal Protective Service (FPS)
5. Discuss the National InfraGard Program, which was a cooperative formed with public
and private organizations to protect critical national information resources. Provide
students with a list of some of the tools provided by this program:
a. Intrusion alert network using encrypted e-mail
d. Help desk for questions
6. Describe the National Security Agency’s role in coordinating, directing, and
performing highly specialized activities to protect U.S. information systems and
produce foreign intelligence information.
7. Note that the NSA’s Information Assurance Directorate (IAD) provides InfoSec
Teaching
See the following law.com link for a more detailed explanation of organizational
Management of Information Security, Fourth Edition 1211
9. Explain to students that the U.S. Secret Service is charged with the detection and arrest
of any person committing a U.S. federal offense relating to computer fraud or false
identification crimes.
Managing Investigations in the Organization
1. Define digital forensics as being based on traditional forensics, which is the application
of methodical investigatory techniques to present evidence of crimes in a court or court-
like setting.
4. Describe e-discovery as the identification and preservation of EM related to a specific
legal action, and note that digital forensics tools and methods may be used to carry out
e-discovery.
5. List the two different purposes for which digital forensics can be used:
a. To investigate allegations of digital malfeasance
b. To perform root cause analysis
6. Define digital malfeasance as a crime against or using digital media, computer
Digital Forensics Team
1. Explain that most organizations cannot sustain a permanent digital forensics team, but
use outsourcing to assign the analysis to a regional expert.
Teaching
More information about FBI’s InfraGard can be found at:
Management of Information Security, Fourth Edition 1212
Affidavits and Search Warrants
1. Explain to students that many investigations begin with an allegation or indication of an
incident, and point out that an organization’s forensics team must then get permission
to examine digital media for evidence.
Digital Forensics Methodology
1. Explain to students that all investigations utilizing digital forensics follow the same
basic methodology:
a. Identify relevant items of evidentiary value (EM)
2. Explain that an organization may want to seek legal advice or consult with local or state
law enforcement when seeking to perform digital forensics.
3. Provide students with an overview of different publications that should be part of a
digital forensics team’s library.
4. Elaborate on how a digital forensics team identifies potential EM and its probable
search warrant or authorization document.
5. Educate students on the potential storage media for EM, such as removable drives,
CDs, DVDs, flash drives, memory chips or sticks, or other computers accessed over an
organization’s network or over the Internet.
6. Describe the problem of obtaining EM from locations that are outside of an
organization’s control, since an organization cannot legally search systems they don’t
own.
7. Make students aware of the fact that some evidence is not electronic or digital in nature.
Teaching
For a more detailed digital forensics analysis methodology flowchart, see the
Management of Information Security, Fourth Edition 1213
Evidentiary Procedures
1. Explain to students that any time an investigation involves digital malfeasance or
performing root cause analysis, the possibility of the results and methods of
investigation being examined in a criminal or civil court should be considered.
policy document regarding forensics.
Quick Quiz 2
1. Items of potential evidentiary value are known as ____________________.
2. True or False: Liability can be applied to conduct even when no law or contract has
been breached.
3. A court’s right to hear a case if an act was committed in its territory or involving its
citizenry is known as __________.
4. What act increased the Secret Service’s role in investigating fraud and related activity
in connection with computers?
A. PATRIOT Act
B. Digital Millennium Copyright Act
C. Computer Fraud and Abuse Act
D. Sarbanes-Oxley Act
5. Which of the following is NOT one of the three general categories of unethical
behavior?
A. Malfeasance
B. Ignorance
C. Accident
D. Intent
Management of Information Security, Fourth Edition 1214
Class Discussion Topics
1. Start a class discussion on the importance of evidence preservation when performing
digital forensics. What could be the results of a loss of evidence, or damaged evidence?
Additional Projects
1. Provide students with different scenarios, and task them with identifying the applicable
laws under which the scenarios would fall under.
Additional Resources
1. NIST SP 800-101 Rev. 1 (Draft) Guidelines on Mobile Device Forensics: