Security, Ethical, and Societal Challenges of Information Technology
Lecture Overview and Objectives
- Primary Lecture Theme: An in-depth exploration of the security, ethical, and societal challenges posed by information technology (IT) in a business context.
- Lecturer: Raguib Raihan.
- Core Learning Objectives:
- Identify several ethical issues regarding how the use of IT in business affects employment, individuality, working conditions, privacy, crime, health, and solutions to societal problems.
- Identify several types of security management strategies and defenses and explain how they can be used to ensure the security of business applications of IT.
- Propose several ways that business managers and professionals can help lessen the harmful effects and increase the beneficial effects of the use of information technology.
- Dimensional Scope: The lecture focuses on three critical dimensions of IT use in business:
- Security dimensions.
- Ethical dimensions.
- Societal dimensions.
- Definition of Business Ethics: Business ethics is concerned with the numerous ethical questions that managers must confront as part of their daily business decision-making processes.
- IT-Driven Ethical Controversies: The advent and spread of information technology have caused significant ethical controversy in the following specific areas:
- Intellectual property (IP) rights.
- Customer and employee privacy.
- Security of company information.
- Workplace safety.
Theories of Ethical Business Responsibility
- Stockholder Theory:
- Holds that managers are agents of the stockholders.
- The only ethical responsibility of a manager is to increase the profits of the business.
- This must be done without violating the law or engaging in fraudulent practices.
- Stakeholder Theory:
- Managers have an ethical responsibility to manage a firm for the benefit of all of its stakeholders.
- Stakeholders are defined as any individuals or groups that have a stake in, or claim on, a company.
- Core Stakeholders: Usually include the corporation’s stockholders, employees, customers, suppliers, and the local community.
- Broadened Stakeholders: Sometimes includes all groups who can affect or be affected by the corporation, such as competitors, government agencies, and special-interest groups.
- Managerial Challenge: Balancing the claims of conflicting stakeholders is recognized as a difficult task for managers.
- Social Contract Theory:
- States that companies have ethical responsibilities to all members of society, as corporations exist according to a social contract.
- First Condition: Companies must enhance the economic satisfaction of consumers and employees. They must do so without:
- Polluting the environment.
- Depleting natural resources.
- Misusing political power.
- Subjecting employees to dehumanizing working conditions.
- Second Condition: Companies must avoid fraudulent practices, show respect for employees as human beings, and avoid practices that systematically worsen the position of any group in society.
Principles and Guidelines for Technology Ethics
- Implementation of Ethics: Principles of technology ethics serve as basic ethical requirements that companies should meet to help ensure the ethical implementation of IT and information systems in business.
- Ethical Health Standards:
- Organizations should address health risks associated with computer workstations used for extended periods, particularly in high-volume data entry positions.
- Ethical Actions: Scheduling work breaks and limiting the time workers stare at monitors to minimize the risk of hand or eye injuries and other work-related health disorders.
- Company Usage Policies:
- Organizations draft detailed policies for ethical computer and Internet usage.
- General Rule: Company computer workstations and networks are company resources and must be used exclusively for work-related purposes, whether using internal networks or the Internet.
- AITP Code of Professional Conduct: Similar to company policies, the Association of Information Technology Professionals (AITP) provides a code of professional conduct.
- Professional Responsibility Guidelines: Professionals can meet ethical responsibilities by voluntarily followed these five codes of conduct:
- 1. Acting with integrity.
- 2. Increasing professional competence.
- 3. Setting high standards of personal performance.
- 4. Accepting responsibility for one's work.
- 5. Advancing the health, privacy, and general welfare of the public.
Computer Crime: Definition and Scope
- Definition of Computer Crime: A pervasive threat to society caused by the criminal or irresponsible actions of individuals taking advantage of the widespread use and vulnerability of computers and networks.
- Impact: Poses serious threats to the integrity, safety, and survival of business systems, making the development of security methods a top priority.
- AITP Definition of Computer Crime: Includes:
- 1. The unauthorized use, access, modification, and destruction of hardware, software, data, or network resources.
- 2. The unauthorized release of information.
- 3. The unauthorized copying of software.
- 4. Denying an end user access to his or her own hardware, software, data, or network resources.
- 5. Using or conspiring to use computer or network resources to obtain information or tangible property illegally.
Types of Computer Crimes and Malicious Software
- Primary Categories:
- Hacking and Cracking.
- Cyber theft.
- Cyber-terrorism and Cyber warfare.
- Unauthorized use at work.
- Software Piracy.
- Theft of Intellectual Property.
- Computer Viruses and Worms.
- Adware and Spyware.
Detailed Breakdown of Hacking and Security Exploits
- Hacking: The obsessive use of computers or unauthorized access and use of networked systems. Hackers can be outsiders or company employees.
- Cracking (Black Hat/Darkside Hacker): A malicious hacker who finds vulnerabilities and exploits them for private advantage, often keeping them secret from the public or manufacturer. They may use access for blackmail or to maliciously cause damage.
- Common Tactics and Exploits:
- Denial of Service (DoS): Hammering a website's equipment with too many requests to clog the system, slowing performance or crashing it. Often used to cover other attacks.
- Vulnerability Scans: Widespread probes of the Internet to determine types of computers and connections to exploit specific weaknesses.
- Packet Sniffer: Programs that covertly search individual data packets passing through the Internet to capture passwords or contents.
- Spoofing (Phishing): Faking an email address or Web page to trick users into providing passwords or credit card numbers.
- Trojan Horse: A program that unknown to the user contains instructions to exploit a vulnerability in software.
- Back Doors: Hidden ways back into a system used if the original entry point is detected.
- Malicious Applets: Tiny programs (often in Java) that misuse computer resources, modify files, send fake emails, or steal passwords.
- War Dialing: Automatically dialing thousands of phone numbers to search for modem connections.
- Logic Bombs: Instructions in a program that trigger a malicious act.
- Buffer Overflow: Crashing or gaining control of a computer by sending too much data to the memory buffer.
- Password Crackers: Software designed to guess passwords.
- Social Engineering: Talking unsuspecting employees out of valuable information like passwords.
- Dumpster Diving: Sifting through company garbage to find information that helps break into computers.
Workplace Ethics and Resource Theft
- Unauthorized Use at Work: Often referred to as "time and resource theft."
- Examples: Using company computers for private consulting, personal finances, playing video games, or unauthorized Internet browsing.
- Monitoring: Organizations use "sniffers" (network monitoring software) to evaluate capacity and reveal evidence of improper use.
Intellectual Property and Software Piracy
- Software Piracy: The unauthorized copying of programs. It is illegal because software is intellectual property protected by copyright law and licensing agreements.
- IP Theft Categories: Infringements on copyrighted music, videos, images, articles, and books.
- Dissemination Methods: Captured digitally and made available for download on websites or sent via email attachments.
Viruses, Worms, Adware, and Spyware
- Viruses: Program code that requires being inserted into another program to function. They copy annoying or destructive routines into systems.
- Worms: Distinct programs that can run unaided. They are capable of spreading destruction by destroying memory and hard disk contents.
- Adware: Software that displays banners and pop-ups without consent, often while appearing to serve a useful function.
- Spyware: A extreme class of adware that employs a user’s Internet connection in the background without permission. It collects demographics, credit card numbers, Social Security numbers (SSN), and surfing habits.
- Additional Spyware Harms:
- Adds advertising links to Web pages.
- Redirects affiliate payments.
- Changes home pages and search settings.
- Forces modems to call premium-rate phone numbers.
- Leaves security holes for Trojans.
- Degrades system performance.
Privacy Issues and Standards
- The Right to Privacy: IT's power to store and retrieve data can negatively affect this right. Personal information is collected with every website visit.
- Opt-In Model: Users must explicitly consent to allow data to be compiled. This is the default standard in Europe.
- Opt-Out Model: Data is compiled unless the user specifically requests it not be. This is the default standard in the United States.
- Specific Violations of Privacy:
- Unauthorized Access: Reading private emails and computer records.
- Computer Monitoring: Constant knowledge of a person's location via mobile and paging services.
- Computer Matching: Using customer info from multiple sources for marketing purposes.
- Unauthorized Access of Personal Files: Collecting telephone numbers, emails, and credit card numbers to build customer profiles.