Chapter 13 – Security and Ethical Challenges
13-1
13 Security and Ethical Challenges
CHAPTER OVERVIEW
Chapter 13: Security and Ethical Challenges discusses the threats against and defenses needed for the
performance and security of business information systems, as well as societal impact and ethical implications of
information technology.
LEARNING OBJECTIVES
1. Identify several ethical issues regarding how the use of information technologies in business affects
employment, individuality, working conditions, privacy, crime, health, and solutions to societal problems.
SUMMARY
• Ethical and Societal Dimensions. The vital role of information technologies and systems in society raises serious
ethical and societal issues in terms of their impact on employment, individuality, working conditions, Summary
privacy, health, and computer crime, as illustrated in Figure 13.2 . Employment issues include the loss of jobsa
result of computerization and automation of workversus the jobs created to supply and support new information
• Ethical Responsibility in Business. Business and IT activities involve many ethical considerations. Basic
principles of technology and business ethics can serve as guidelines for business professionals when dealing with
Chapter 13 – Security and Ethical Challenges
13-2
• Security Management. One of the most important responsibilities of the management of a company is to ensure
the security and quality of its IT-enabled business activities. Security management tools and policies can ensure the
KEY TERMS AND CONCEPTS
2. Audit Trail (570):
Documentation that allows a transaction to be traced through all stages of its information processing.
3. Backup Files (565):
4. Biometric Security (566):
6. Computer Crime (534):
Computer crime is defined by the Association of Information Technology Professionals (AITP) as including (1)
7. Computer Matching (548):
Using computers to match data about individuals provided by a variety of databases in order to identify
individuals for business, government, or other purposes.
8. Computer Monitoring (551):
9. Computer Virus (542):
10. Cyber law (550):
Encompasses a wide variety of political and legal issues related to the Internet and other communications
technology, including intellectual property, privacy, freedom of expression, and legal jurisdiction.
Chapter 13 – Security and Ethical Challenges
13-3
11. Disaster Recovery (569):
12. Distributed denial of service (561):
Is a process whereby hackers overwhelm a website with requests for service from captive computers also
known as zombies.
13. Encryption (559):
14. Ergonomics (553):
15. Ethical Foundations (528):
16. Fault Tolerant (567):
17. Firewall (560):
A computer that protects computer networks from intrusion by screening all network traffic and serving as a
safe transfer point for access to and from other networks.
18. Flaming (550):
19. Hacking (535):
Hacking comprises gaining unauthorized access to and use of a computer system.
2
20. Information System Controls (569):
21. Intellectual Property Theft (541):
22. Opt-in/Opt-out (546):
23. Passwords (565):
24. Security Management (555):
Passwords, identification codes, account codes, and physical barriers that limit the access and use of computer
based system resources to authorized users.
Chapter 13 – Security and Ethical Challenges
13-4
25. Societal solutions (553):
Using information systems to help solve social problems.
25. Software Piracy (540):
Unauthorized copying of software.
27. Spyware/Adware (544):
A broad category of software intended to intercept communications or take partial control of a computer’s
28. System Security Monitor (566):
29. Unauthorized Use (538):
Unauthorized use comprises computer time and resource theft and violations of an applications terms of use or a
website’s terms of service agreements.
ANSWERS TO REVIEW QUIZ
Q.
A.
Key Term
Q.
A.
1
24
Security management
16
7
2
20
Information system controls
17
8
3
29
System security monitor
18
12
4
16
Fault tolerant
19
6
5
17
Firewall
20
30
6
10
Cyber law
21
26
7
2
Audit trail
22
21
8
4
Biometric security
23
19
9
11
Disaster recovery
24
9
10
13
Encryption
25
1
11
15
Ethical foundations
26
18
12
5
Business ethics
27
14
13
Spamming
28
25
14
Spyware/Adware
29
3
15
22
30
23
Chapter 13 – Security and Ethical Challenges
13-5
ANSWERS TO DISCUSSION QUESTIONS
1. What can be done to improve the security of business uses of the Internet? Give several examples of
security measures and technologies you would use.
Examples:
Encrypt all stored data
Encrypt all data transmissions
Install firewalls
2. What potential security problems do you see in the increasing use of intranets and extranets in business?
What might be done to solve such problems? Give several examples.
Potential problems:
Motivation. Due to the wide spread adoption of Internet technologies, business have given hackers a large
Solutions:
Engage security auditors to review all security precautions periodically and randomly.
Keep system software updated. While it make sense to take advantage of the cost savings associated with
Chapter 13 – Security and Ethical Challenges
3. Refer to the real-world example about copying CDs and music downloading in the chapter. Is copying
music CDs an ethical practice? How about Internet music downloading? Explain.
Copying:
It is rarely ethical to violate the law. In the case of entertainment and intellectual property, it is not ethical to
violate the law. Copying a CD or other copyrighted files is legal if the person making the copy owns the rights
codes is also not legal.
Downloading:
It is ethical to download music or other intellectual property so long as it is in compliance with its copyright.
4. What are your major concerns about computer crime and privacy on the Internet? What can you do
about it? Explain.
Concerns:
Identity theft
Fraud
5. What is disaster recovery? How could it be implemented at your school or work?
Definition: Disaster recovery includes methods for ensuring that an organization recovers quickly and
effectively from natural or human caused disasters that affect its computer-based operations.
Chapter 13 – Security and Ethical Challenges
13-7
6. Refer to the Real World Case on IT and ethics in the chapter. Most or all companies have an ethics and
compliance program of some sort, but not all of them “live” by it. What does it take for a company to
take this next step? What is the role of IT in that scenario?
Taking the next step
Formulate the standards
Communicate with the public
7. Is there an ethical crisis in business today? What role does information technology play in unethical
business practices?
Yes The collapse of Enron, WorldCom, Arthur Andersen, and others as well as legislation making CEOs (and
8. What are several business decisions that you will have to make as a manager that have both ethical and
IT dimensions? Give examples to illustrate your answer.
Example decisions:
Modernizing replacing people with applications
Chapter 13 – Security and Ethical Challenges
13-8
9. Refer to the Real World Case on endpoint security in the chapter. How do companies strike a balance
between providing users with access to the information they need in the form that is most useful to them,
while at the same time enforcing adequate security? What issues should organizations consider when
making this decision?
Striking a balance
Device connected some devices can be more easily secured than others
Physical security some data can only be accessed from very specific locations
10. What would be examples of one positive and one negative effect of the use of information technologies in
each of the ethical and societal dimensions illustrated in Figure 13.2 ? Explain several of your choices.
Employment:
Pro: IT has created many new jobs and increased productivity and efficiency.
Con: IT has caused a significant reduction in mid-level management positions.
Privacy:
Chapter 13 – Security and Ethical Challenges
13-9
VII. ANSWERS TO ANALYSIS EXERCISES
1. Problems with passwords: Authentication
a. Biometrics (biological measuring)
Biometrics involves measuring an immutable and unique physical trait and using these measures to identify an
Advantages
Biometrics eliminates the problems associated with passwords. Users don’t need to remember their biometrics
or to remember to bring their biometrics with them.
Disadvantages
Biometric systems possess varying degrees of accuracy. Given a large enough sample group, two individuals
b. Smart cards
Smart cards have an embedded processor that can not be copied as easily as the magnetic strips on credit cards
or ATM cards.
Advantages
c. Biochips
These are essentially RFID tags implanted under the skin. Numerous municipalities have been using bio-chips
instead of tags for dog and cat registration. Bio chip authentication systems send out radio waves, and the chips
4
The popular TV program “Mythbusters” included an episode illustrating (but not detailing) how they were able to
create a fake fingerprint to defeat a sophisticated fingerprint scanner.
Chapter 13 – Security and Ethical Challenges
1310
Disadvantages
Criminals can forcibly remove and reuse a chip. People might resist having such a chip implanted for that
2. Your Internet Job Rights: Three Ethical Scenarios
a. Do you agree with the advice of attorney Mark Grossman in each of the scenarios? Why or why not?
Scenario 1:
Agree: the employee should have known better and focused his or her time on productive activities. Whether
b. What would your advice be? Explain your positions.
Scenario 1:
The employer should have trained new employees more effectively. The employee should find an employer
more focused on productivity than on monitoring behavior.
c. Identify any ethical principles you may be using to explain your position in each of the scenarios.
Ethical principles include:
Privacy governing the individual
3. Exploiting Security Weaknesses: Social Engineering
a. Describe the business problems that this exercise presents.
Information systems are vulnerable to “social engineering.”
b. Suggest several ways to reduce an organization’s exposure to social engineering.
Improve employee training at all levels and responsibility.
Chapter 13 – Security and Ethical Challenges
1311
c. Prepare an orientation memo to new hires in your IT department describing “social engineering.”
Suggest several ways employees can avoid being tricked by hackers.
MEMO:
To: All systems administrative employees.
Imposters posing as employees may request accounts, passwords, and other information. Even by giving out
employee names or instructions about how to obtain access, you may be helping a hacker gain access to our
systems. Our future and our jobs depend upon keeping our systems secure.
4. Privacy Statements: The Spyware Problem
a. Use a search engine to search for “spyware,” “spyware removal,” “adware,” or other related terms.
Prepare a one-page summary of your results. Include URLs for online sources.
Adware, spyware, and cookies have caused great consternation among many Internet users. Students will have
no difficulty finding information about how this software is used and how to remove it.
Students may be surprised to learn that many popular peer-to-peer file sharing programs come complete with
“adware.”
Description
URL
Chapter 13 – Security and Ethical Challenges
1312
b. Select three of your favorite Web sites and print out their privacy policies. What do they share in
common? How do they differ?
Consider having students simply highlight the common elements in one color and the unique elements with
another color on each printout.
c. Write your own Web site privacy policy, striking a balance between customer and business needs.
Policies should include statements about data collection and methods, security (especially of credit
ANSWERS TO REAL WORLD CASES
RWC 1: Texas Health Resources and Intel
Case Study Questions
1. What are the two meanings of ‘corporate ethics’ in organizations today? What does each definition imply
for IT practices? How does the economic environment affect this?
Meaning 1
The set of legal and minimum standards. This sets the bar as low as possible and opens up the usefulness of
lobbying legislators for even lower standards.
2. How does IT provide more opportunities for difficult ethics issues to arise? How does IT help address
those?
Ethical issues
Personal privacy
Chapter 13 – Security and Ethical Challenges
1313
IT’s role
Advising senior management
3. Use examples from the case to justify your answer.
Examples
Screen vendors
4. Should organizations pursue high ethical standards regardless (or in spite of) their bottom-line impact?
Or should they limit themselves to those scenarios where “good ethics make for good business”?
Organizations that fail to compete fail. Organizations can implement high ethical standards than legally
required only when:
Real World Activities
1. The passage of the Sarbanes-Oxley Act in the United States has greatly increased the compliance
obligations of publicly traded companies. Go online to research how this landmark legislation affected the
obligations of IT departments, and the way in which they develop and implement new technologies. Prepare a
presentation to synthesize your findings.
Search
2. Should an IT department hire a more expensive vendor because the vendor shares its own company’s
ethics standards, or should it go with a lower-cost provider that doesn’t? This is an important question posed
in the case above. What do you think? Break into small groups with your classmates to discuss your positions.
Can you reach a consensus on this issue?
Yes if these standards are part of the organization‘s strategy or image. Otherwise the organization faces the
Chapter 13 – Security and Ethical Challenges
1314
RWC 2: Wyoming Medical Center, Los Angeles County, and Raymond James
Case Study Questions
1. What is the underlying issue behind endpoint security, and why is it becoming even more difficult for
companies to address it? Define the problem in your own words using examples from the case.
Underlying issues
Employees want the convenience that goes with connecting their own devices
5
Employers want to meet their employees expectations
2. What are the different approaches taken by the organizations in the case to address this issue? What are
the advantages and disadvantages of each? Provide at least two examples for each alternative.
Approaches
Trust advantages: It’s cheap and easy.
3. A majority of respondents to a survey discussed in the case described their company as “trusting.” What
does this mean? What is the upside of a company being “trusting”? What is the downside? Provide some
examples to illustrate your answers.
Upside
“Trusting” is easy to implement and provides maximum convenience for users.
Downside
Chapter 13 – Security and Ethical Challenges
1315
Real World Activities
1. Data loss prevention (DLP) was a technology mentioned in the case, and one that is garnering more and
more attention from corporate security departments. Go online and research what DLP involves, and look for
examples of its application to actual problems, and their outcomes. Prepare a report to summarize your
work.
Application examples
Search Google News for “data loss prevention” technology
2. Whether to allow employees to use their own smartphones (or other devices yet to be invented) on
corporate networks is quickly becoming a contested issue. What do companies stand to gain, or lose, in either
case? What about employees? Break into small groups with your classmates to discuss these questions.
Organizations gain
Flexible employees
Organizations lose
Organizations end up with significantly more data end-points to manage
Employees gain
Flexibility work from more locations
Employees lose
Work travels home and on vacation
Productivity (or value) may be difficult to evaluate or fully appreciate
RWC 3: Ethics, Moral Dilemmas, and tough Decisions
Case Study Questions
1. Companies are developing ethical policies and guidelines for legal reasons, but also to clarify what is
acceptable and what is not. Do you think any of the issues raised in the case required clarification? Would
you take exception to any of them being classified as inappropriate behavior? Why do you think these things
happen anyway?
Chapter 13 – Security and Ethical Challenges
1316
Clarification:
What do people have a legal obligation to report?
What do organizations have a legal obligation to report?
Exception: No. Employees are obligated to use their time and organization’s resources for the sole benefit of
their employer. Any other use is inappropriate unless specifically allowed by the employer.
Causality:
2. In the first example (Bryan’s), it is apparent that he did not believe justice had been ultimately served by
the decision his company made. Should he have taken the issue to the authorities? Or was it enough that he
reported the problem through the proper channels and let the organization handle it, as was the
recommendation of Linn Hynds? Provide a rationale for the position you are willing to take on this matter.
In Bryan’s mind, he exchanged economic security for his family for the likelihood of continued child sexual
abuse. This is a decision that will haunt him the rest of his life, not to mention the potential suffering of future
victims.
a significant difference in the outcome of an active investigation.
3. In the case, Gary chose not to stop his boss from installing unlicensed software, although he refused to do
it himself. If installing unlicensed software is wrong, is there any difference between refusing to do it versus
not stopping somebody else? Do you buy his argument that it was not really going to hurt anybody? Why or
why not?
Society functions better if people follow the law and seek to change the law through legal means when needed.
Real World Activities
1. Go online to follow up on John Mackey’s story and search for other instances of debatable behavior
where IT has been an important factor. Are the ones featured in the case exceptions, or are these occurrences
becoming more and more common? How do organizations seem to be coping with these issues? What type of
responses did you find? Prepare a report to summarize your findings.
Chapter 13 – Security and Ethical Challenges
1317
As of August 2008, Mackey has been cleared by the SEC of wrongdoing, and his company’s board of directors
has expressed full faith in him as CEO. Mackey has resumed blogging. Mackey’s mistake was in not
2. The case features many examples of what is arguably unethical behavior, including child pornography,
accessing adult content on company-owned equipment, installing unlicensed software, and so on. Are some of
these practices “more wrong” than others? Is there any one that you would not consider problematic? Break
into small groups to discuss these questions and make a list of other ethical problems involving IT that were
not mentioned in the case.
The behaviors outlined in this case can be broken down into several categories.
Criminal activity: accessing child pornography or participating in software piracy are crimes and should be
treated as such. The case doesn’t mention hacking, but this activity also falls under the “criminal activity”
heading.
Civil liabilities: accessing pornography or “hate speech” can contribute to a “hostile work environment” and
Other ethical problems:
bullying
liable
RWC 4: Raymond James Financial, BCD Travel, Houston Texans, and Others
Case Study Questions
1. Barring illegal activities, why do you think that employees in the organizations featured in the case do not
realize themselves the dangers of loosely managing proprietary and sensitive information? Would you have
thought of these issues?
Chapter 13 – Security and Ethical Challenges
1318
These managers probably have not seen examples of communications going out nor have they seen hackers in
2. How should organizations strike the right balance between monitoring and invading their employees’
privacy, even if it would be legal for them to do so? Why is it important that companies achieve this balance?
What would be the consequences of being too biased to one side?
Organizations have an obligation to maintain their customer’s privacy. Indeed, if they lose their customer’s
3. The IT executives in the case all note that outbound monitoring and management technologies are only
part of an overall strategy, and not their primary defense. What should be the other components of this
strategy? Which weight would you give to human and technological factors? Why?
Other components:
access control
Real World Activities
1. Technologies such as VoIP used by Skype and similar products make it more difficult to monitor
outgoing information. Search the Internet to help you understand these technologies and why these problems
arise. Other than banning them, what alternatives would you suggest to companies facing this problem?
Prepare a presentation to deliver your recommendations.
VoIP technologies comprise voice communications. Commercial speech translation software simply isn’t
2. As a customer of many of the companies noted in the case, or others in the same industries, what is your
expectation about the measures and safeguards that these organizations have implemented to protect
inappropriate leaking of your personal information? After reading the case, has your expectation changed?
Break into small groups with your classmates to discuss these issues.
Chapter 13 – Security and Ethical Challenges
I would expect organizations to employ industry standard safeguards. These safeguards would depend on the industry.