Chapter 2 - Law and Ethics Flashcards
Deterrence: the act of attempting to prevent by threatening punishment if action takes place.
using policy, training and technology, infosec personnel deter unethical and illegal acts.
best method to prevent unethical behaviour. example of deterrence is laws, policies and associated penalties.
Penalties only deter when:
- dear of penalty
- probability of being caught
- probability of penalty being administered
Professional Organisations:
Association of Computing Machinery (ACM): worlds first educational and scientific computing society.
ISC2: non profit organisation that focuses on the development and implementation of InfoSec certification and credentials.
SANS: professional research and education cooperative organisation.
ISACA: professional organisation with a focus on auditing, control, and security.
ISSA: nonprofit society of Infosec professionals. bringing professionals together for information exchange and educational development.
The key difference between policy and law
ignorance of law is not an excuse, ignorance of policy is a viable defense.
due care
due diligence
liability
restitution
long arm jurisdiction
due care: to make sure that every employee knows what is acceptable and what is not
due diligence: requires that an organisation make a valid and ongoing effort to protect others.
restitution: make compensation or payment resulting from loss. tazminat..
long arm jurisdiction: that a court of can judge a defendant across the country or worldwide. there are limitations..
e-discovery: collecting, identifying,… electronic evidence for a lawsuit or investigation.
forensic allows investigators to determine what happened but don’t do to figure out why happened.
Digital forensic methodology:
- Identify relevant items of evidentiary value (EM)
- Acquire the evidence without altering it. usually is done by imaging the evidence. Chain of evidence should be recorded in detail.
- Authenticate the evidence at every step taken
- Analyse the data without making changes. First step of analysis is indexing the data.
- Report the findings to the proper authority