Chapter 13 – Security and Ethical Challenges
13-1
13 Security and Ethical Challenges
CHAPTER OVERVIEW
Chapter 13: Security and Ethical Challenges discusses the threats against and defenses needed for the
performance and security of business information systems, as well as societal impact and ethical implications of
information technology.
LEARNING OBJECTIVES
1. Identify several ethical issues regarding how the use of information technologies in business affects
employment, individuality, working conditions, privacy, crime, health, and solutions to societal problems.
SUMMARY
• Ethical and Societal Dimensions. The vital role of information technologies and systems in society raises serious
ethical and societal issues in terms of their impact on employment, individuality, working conditions, Summary
privacy, health, and computer crime, as illustrated in Figure 13.2.
Employment issues include the loss of jobsa result of computerization and automation of workversus the jobs
• Ethical Responsibility in Business. Business and IT activities involve many ethical considerations. Basic
principles of technology and business ethics can serve as guidelines for business professionals when dealing with
Chapter 13 – Security and Ethical Challenges
13-2
• Security Management. One of the most important responsibilities of the management of a company is to ensure
the security and quality of its IT-enabled business activities. Security management tools and policies can ensure
KEY TERMS AND CONCEPTS
1. Antivirus Software ():
A software program designed to find, mitigate, and/or eliminate computer viruses.
2. Audit Trail ():
Documentation that allows a transaction to be traced through all stages of its information processing.
3. Backup Files ():
4. Biometric Security ():
Computer-based security methods that measure physical traits and characteristics such as fingerprints, voice
prints, retina patterns, or other unique traits.
6. Computer Crime ():
(2) the unauthorized release of information; (3) the unauthorized copying of software; (4) denying an end user
7. Computer Matching ():
Using computers to match data about individuals provided by a variety of databases in order to identify
individuals for business, government, or other purposes.
8. Computer Monitoring ():
9. Computer Virus ():
10. Cyber law ():
Encompasses a wide variety of political and legal issues related to the Internet and other communications
technology, including intellectual property, privacy, freedom of expression, and legal jurisdiction.
Chapter 13 – Security and Ethical Challenges
13-3
11. Disaster Recovery ():
Methods for ensuring that an organization recovers from natural and human-caused disasters that affect its
computer-based operations.
12. Distributed denial of service ():
13. Encryption ():
14. Ergonomics ():
15. Ethical Foundations ():
Choices resulting from decision-making processes or behavioral stages which include egoism, natural law,
utilitarianism, and respect for persons.
16. Fault Tolerant ():
17. Firewall ():
18. Flaming ():
19. Hacking ():
Hacking comprises gaining unauthorized access to and use of a computer system.
2
20. Information System Controls ():
Methods and devices that attempt to ensure the accuracy, validity, security, and propriety of information system
activities.
21. Intellectual Property Theft ():
22. Opt-in/Opt-out ():
23. Passwords ():
24. Security Management ():
Passwords, identification codes, account codes, and physical barriers that limit the access and use of computer
based system resources to authorized users.
2
In at least one case, “unauthorized use” included a user simply violating a website’s terms of service agreement.
Chapter 13 – Security and Ethical Challenges
13-4
25. Software Piracy ():
Unauthorized copying of software.
26. Spamming ():
The indiscriminate sending of unsolicited commercial e-mail (UCE) to many Internet users.
27. Spyware/Adware ():
A broad category of software intended to intercept communications or take partial control of a computer’s
28. System Security Monitor ():
29. Unauthorized Use ():
Unauthorized use comprises computer time and resource theft and violations of an applications terms of use or a
website’s terms of service agreements.
ANSWERS TO REVIEW QUIZ
Q.
A.
Key Term
Q.
A.
1
Security management
16
2
Information system controls
17
3
System security monitor
18
4
Fault tolerant
19
5
Firewall
20
6
Cyber law
21
7
Audit trail
22
8
Biometric security
23
9
Disaster recovery
24
10
Encryption
25
11
26
12
Business ethics
27
13
Spamming
28
14
Spyware/Adware
29
15
30
Chapter 13 – Security and Ethical Challenges
13-5
ANSWERS TO DISCUSSION QUESTIONS
1. What can be done to improve the security of business uses of the Internet? Give several examples of
security measures and technologies you would use.
Examples:
Encrypt all stored data
Encrypt all data transmissions
2. What potential security problems do you see in the increasing use of intranets and extranets in business?
What might be done to solve such problems? Give several examples.
Potential problems:
Motivation. Due to the wide spread adoption of Internet technologies, business have given hackers a large
motivation to crack and exploit these technologies.
Solutions:
Engage security auditors to review all security precautions periodically and randomly.
Keep system software updated. While it make sense to take advantage of the cost savings associated with
Chapter 13 – Security and Ethical Challenges
13-6
3. Refer to the real-world example about copying CDs and music downloading in the chapter. Is copying
music CDs an ethical practice? How about Internet music downloading? Explain.
Copying:
It is rarely ethical to violate the law. In the case of entertainment and intellectual property, it is not ethical to
violate the law. Copying a CD or other copyrighted files is legal if the person making the copy owns the rights
Downloading:
It is ethical to download music or other intellectual property so long as it is in compliance with its copyright.
4. What are your major concerns about computer crime and privacy on the Internet? What can you do
about it? Explain.
Concerns:
Identity theft
Solutions:
Do not post personal information on the Internet
5. What is disaster recovery? How could it be implemented at your school or work?
Definition: Disaster recovery includes methods for ensuring that an organization recovers quickly and
effectively from natural or human caused disasters that affect its computer-based operations.
Implementation: A disaster recovery plan should specify which employees will participate in disaster
6. Refer to the Real World Challenge in the introduction to this chapter. Should “IS” security be managed
in a different way than physical security? How are the two areas different? How are they similar?
Manage them the same: This is a result of seeing security as an organization-wide Strategic function. As a
Chapter 13 – Security and Ethical Challenges
13-7
made between managing security for physical issues or electronic issues.
Manage them differently: Managing physical and electronic security differently comes about by seeing
Differences and Similarities: As more and more business is done electronically, the two areas grow closer and
begin to overlap. Traditional definitions would give Physical security the responsibility for doors of entry,
7. Is there an ethical crisis in business today? What role does information technology play in unethical
business practices?
Yes The collapse of Enron, WorldCom, Arthur Andersen, and others as well as legislation making CEOs (and
8. What are several business decisions that you will have to make as a manager that have both ethical and
IT dimensions? Give examples to illustrate your answer.
Example decisions:
Modernizing replacing people with applications
9. Refer to the Real World Solution in the chapter. Can you apply the “likelihood and magnitude”
approach to any kind of risk that a company faces? Can you think of any examples that would not be
suitable for that kind of analysis? How should companies evaluate those situations?
Any risk can be looked at from the “likelihood and magnitude” approach, the problem being how to determine
Chapter 13 – Security and Ethical Challenges
13-8
10. What would be examples of one positive and one negative effect of the use of information technologies in
each of the ethical and societal dimensions illustrated in Figure 13.2 ? Explain several of your choices.
Employment:
Pro: IT has created many new jobs and increased productivity and efficiency.
Con: IT has caused a significant reduction in mid-level management positions.
Privacy:
Pro: Caller identification may allow users to screen out telemarketers or prank callers.
Con: IT allows supervisors to monitor an employee’s private conversations.
ANSWERS TO ANALYSIS EXERCISES
1. Problems with passwords: Authentication
source for current news articles featuring these topics.
a. Biometrics (biological measuring)
Biometrics involves measuring an immutable and unique physical trait and using these measures to identify an
individual. This process requires that a person has previously “registered” with the system. The following
Chapter 13 – Security and Ethical Challenges
b. Smart cards
A smart card involves the possession of an object such as a card or computer chip as well as a password for
authentication. ATM cards operate on this principle.
Advantages
This solves the problems associated with theft or social engineering. A user might unwittingly give out his or
c. Biochips
These are essentially RFID tags implanted under the skin. Numerous municipalities have been using bio-chips
instead of tags for dog and cat registration. Bio chip authentication systems send out radio waves, and the chips
3
The popular TV program “Mythbusters” included an episode illustrating (but not detailing) how they were able to
create a fake fingerprint to defeat a sophisticated fingerprint scanner.
Chapter 13 – Security and Ethical Challenges
1310
2. Your Internet Job Rights: Three Ethical Scenarios
Students’ answers will vary. However, students would be well advised to ensure that they are fully versed on any
Internet policies that exist in the workplace. Certainly, when push comes to shove the courts would favor the
a. Do you agree with the advice of attorney Mark Grossman in each of the scenarios? Why or why not?
Scenario 1:
Agree: the employee should have known better and focused his or her time on productive activities. Whether
b. What would your advice be? Explain your positions.
Scenario 1:
The employer should have trained new employees more effectively. The employee should find an employer
c. Identify any ethical principles you may be using to explain your position in each of the scenarios.
Ethical principles include:
Privacy governing the individual
3. Exploiting Security Weaknesses: Social Engineering
a. Describe the business problems that this exercise presents.
Information systems are vulnerable to “social engineering.” Highly trained, expensive technical resources are
required to manage the access control administrative process.
b. Suggest several ways to reduce an organization’s exposure to social engineering.
Improve employee training at all levels and responsibility.
Chapter 13 – Security and Ethical Challenges
1311
actions, and to asses damage after a violation is discovered.
c. Prepare an orientation memo to new hires in your IT department describing “social engineering.”
Suggest several ways employees can avoid being tricked by hackers.
MEMO:
To: All systems administrative employees.
Imposters posing as employees may request accounts, passwords, and other information. Even by giving out
employee names or instructions about how to obtain access, you may be helping a hacker gain access to our
systems. Our future and our jobs depend upon keeping our systems secure.
4. Privacy Statements: The Spyware Problem
a. Use a search engine to search for “spyware,” “spyware removal,” “adware,” or other related terms.
Prepare a one-page summary of your results. Include URLs for online sources.
Adware, spyware, and cookies have caused great consternation among many Internet users. Students will have
no difficulty finding information about how this software is used and how to remove it.
Description
URL
Anti-spyware software vendor’s overview
www.spychecker.com/spyware.html
Anti-spyware software vendor’s overview
www.lavasoftusa.com
Chapter 13 – Security and Ethical Challenges
1312
b. Select three of your favorite Web sites and print out their privacy policies. What do they share in
common? How do they differ?
Students’ answers will vary. Consider having students simply highlight the common elements in one color and
c. Write your own Web site privacy policy, striking a balance between customer and business needs.
Students’ answers will vary. Policies should include statements about data collection and methods, security
(especially of credit information), policy prominence/notification, and opt-in/opt-out information sharing.
5. Security and Ethics
Solutions:
a) If Assange is prosecuted in the U.S., who gets to decide if he broke the law?
Juries judge for themselves the facts of a case and are solely responsible for producing a “guilty” or “not guilty”
verdict (unless the defendant has waved his or her right to a trial by jury and requests a “bench trial” in which case
the judge decides).
b) Should Manning qualify as a “whistleblower?”
c) Was Assange’s publication of the diplomatic cables ethical?
Ethical comes from the Greek ethos, meaning what is RIGHT, unchanging over time, location or situation. So, is
exist.
d) Was Assange’s publication of the video moral?
Moral comes from the Latin mores, meaning what is acceptable, changing over time, location, and situation. If
Manning believed he was protecting Americans from being significantly misled by their government, then his
Chapter 13 – Security and Ethical Challenges
1313
ANSWERS TO REAL WORLD CHALLENGE/SOLUTION
Real World Challenge
1. How should John Petrie handle the fact that, realistically, not all security issues are equally important?
In any case, how do you define importance in this context?
Recommendations
analyze threat
Prioritization
assess probability of the threat materializing
estimate the financial impact of a successful attack
2. What does the reporting structure of a company say about the importance of a particular function or
department? What changes, if any would you make at Harland Clarke?
Reporting structure
the shorter the distance between a function or department and top management, the more important the
function
Recommended changes
provide a “hotline” to top management
3. How do you get people who are not usually security-conscious, or at least never had to be, to be more
aware of the potential security implications of their daily routines? What kind of initiatives would you
introduce? Provide some examples.
Employee training & motivational initiatives
procure or produce training videos that reenact various threat scenarios
Real World Solution
1. How has the way in which decisions about security were made change with the new approach? What are
the key differences? What are the most likely effects of the new procedures?
Changes in security decision making
quality process teams now includes a security component
Chapter 13 – Security and Ethical Challenges
1314
Most likely effects
increase security awareness throughout the organization (cultural shift)
2. Should companies always patch and fix all systems immediately? Why would they take the risk of not
doing so? Can you think of any other examples beyond those presented in the case?
Should companies immediately patch their systems?
no
Why take the risk?
ANSWERS TO REAL WORLD CASES
RWC 1: Texas Health Resources and Intel
Case Study Questions
1. What are the two meanings of ‘corporate ethics’ in organizations today? What does each definition imply
for IT practices? How does the economic environment affect this?
Meaning 1
The set of legal and minimum standards. This sets the bar as low as possible and opens up the usefulness of
lobbying legislators for even lower standards.
Chapter 13 – Security and Ethical Challenges
2. How does IT provide more opportunities for difficult ethics issues to arise? How does IT help address
those?
Ethical issues
Personal privacy
Duty to inform personal information theft victims
IT’s role
Advising senior management
3. Use examples from the case to justify your answer.
Examples
Screen vendors
4. Should organizations pursue high ethical standards regardless (or in spite of) their bottom-line impact?
Or should they limit themselves to those scenarios where “good ethics make for good business”?
Organizations that fail to compete fail. Organizations can implement high ethical standards than legally
Real World Activities
1. The passage of the Sarbanes-Oxley Act in the United States has greatly increased the compliance
obligations of publicly traded companies. Go online to research how this landmark legislation affected
the obligations of IT departments, and the way in which they develop and implement new technologies.
Prepare a presentation to synthesize your findings.
Search
Chapter 13 – Security and Ethical Challenges
1316
2. Should an IT department hire a more expensive vendor because the vendor shares its own company’s
ethics standards, or should it go with a lower-cost provider that doesn’t? This is an important question
posed in the case above. What do you think? Break into small groups with your classmates to discuss
your positions. Can you reach a consensus on this issue?
RWC 2: Wyoming Medical Center, Los Angeles County, and Raymond James
Case Study Questions
1. What is the underlying issue behind endpoint security, and why is it becoming even more difficult for
companies to address it? Define the problem in your own words using examples from the case.
Underlying issues
Employees want the convenience that goes with connecting their own devices
4
Increasing difficulty
Hackers continue to increase their sophistication
Problem defined
Workers want easy access to the tools they need to do their job and make their lives more convenient.
Organizations have an obligation to protect themselves and the personal data entrusted to them. These two
goals will conflict without due care and consideration at the technical, managerial, and executive levels.
2. What are the different approaches taken by the organizations in the case to address this issue? What are
the advantages and disadvantages of each? Provide at least two examples for each alternative.
Approaches
Trust advantages: It’s cheap and easy.
Trust disadvantage: It doesn’t work unless there’s nothing dangerous or valuable to lose.
Chapter 13 – Security and Ethical Challenges
1317
3. A majority of respondents to a survey discussed in the case described their company as “trusting.” What
does this mean? What is the upside of a company being “trusting”? What is the downside? Provide some
examples to illustrate your answers.
Upside
“Trusting” is easy to implement and provides maximum convenience for users.
Downside
Real World Activities
1. Data loss prevention (DLP) was a technology mentioned in the case, and one that is garnering more and
more attention from corporate security departments. Go online and research what DLP involves, and
look for examples of its application to actual problems, and their outcomes. Prepare a report to
summarize your work.
Application examples
2. Whether to allow employees to use their own smartphones (or other devices yet to be invented) on
corporate networks is quickly becoming a contested issue. What do companies stand to gain, or lose, in
either case? What about employees? Break into small groups with your classmates to discuss these
questions.
Organizations gain
Flexible employees
Chapter 13 – Security and Ethical Challenges
Employees gain