Chapter 14 Information Security
248
Chapter 14
Information Security
Objectives and Overview
risks and to provide approaches for managing them from a managerial perspective. The emphasis
Teaching Suggestions
o protect their own
microcomputers against viruses, the information security topic will probably need little
motivation. For courses with in-residence students we have found that a guest lecture by the
ess continuity planning manager can also be
used to help business and IS students understand the information security role in an organization.
One case study in Part IV is directly relevant for this topic:
Case Study IV-9, A Security Breach on the Indiana University Computer Network describes
a situation where a person was able to access a file containing names and social security numbers
of Indiana University faculty members and then posted this file on his personal Web site. It can
Another example of the important role that computer networks, software applications, and IS
leadership roles can play today in the context of a health epidemic has also been documented. For
Chapter 14 Information Security
249
Review Questions
1. What are some examples of computer crime?
Some crimes directly target computers or networks; other crimes use computers and/or networks
2. What is the difference between a hacker and a cracker?
3. What is the role of a chief security officer, and why is this organizational role a relatively
new one?
4. What are the overall goals of information risk management?
5. What resources can organizations use to calculate an expected annual financial loss for a
given information asset?
The best sources to use here are based on the (1) historical experiences of the organization and (2)
6. Why does the Sarbanes-Oxley Act impact the work of IT personnel?
The Sarbanes-Oxley Act of 2002 (SOX) was passed in response to the corporate financial
250
7. Why is it important for an organization to have an information security policy?
8. What is the specific purpose of an acceptable use policy?
9. What information security issues does electronic records management address?
Discussion Questions
1. Do you think the acts of hackers should be punished the same as those by crackers?
Why or why not?
2. Use the Internet to identify a recent report of a computer crime, and summarize what
it involved and what the punishment (if any) was.
Sample Answer: The first phishing scam involving the social networking Web sites Facebook
was recently reported. The Faceboo
Chapter 14 Information Security
3. The importance of having vigilant IT professionals who are capable of detecting and
minimizing the damage from a security breach has become increasingly important. Is
this a type of job position that you would like to hold, and why or why not?
4. If you were offered the position of a CSO for a large organization, what reporting
relationship would you want? Under what circumstances do you think a reporting
relationship to the CIO is the best choice?
5. To achieve SOX compliance has required many organizations to significantly change
their business processes and invest in new software products. Use the Internet to
research some examples of these types of impacts that SOX has had on U.S.-based
companies in particular or J-SOX has had on Japanese companies?
6. HIPAA concerns will be growing over the next years as more physician practices in
the United States adopt electronic health records (to take advantage of a federal
government incentive plan under the HITECH Act). Find a recent article that discusses
concerns about the security of health information of patients.
7. Reflect on when you last received authority to have a computer account with an
organization (e.g., your university), and comment on your own experience when you
were asked to sign (or otherwise signify acceptance of) an organizational policy similar
to the acceptable use policy described in this chapter. Would you recommend any
changes to the organization for what to include in the policy and how to present this
policy to a new account holder?
Chapter 14 Information Security
252
8. How easy is it to find out about an information security policy (e.g., an acceptable use
policy) at your university? At an organization where you are an employee?
9. What were some of the lessons learned about business continuity planning that can be
derived from organizational experiences following the 9/11 attack on the World Trade
Center in New York or Hurricane Katrina in 2005?
10. Use the Internet to research some of the IT-related issues that had to be addressed
by organizations (or individuals) in a recent natural disaster in your own country.
11. What have been some of the impacts of the eDiscovery amendments on U.S.
organizations?