Lecture 3 Flashcards
?
rules that mandate or prohibit certain societal behavior
Law and Ethics in Information Security
Legal, Ethical, and Professional Issues in Information Security
Laws
?
define socially acceptable behavior
Law and Ethics in Information Security
Legal, Ethical, and Professional Issues in Information Security
Ethics
?
fixed moral attitudes or customs of a particular group; ethics based on these
Law and Ethics in Information Security
Legal, Ethical, and Professional Issues in Information Security
Cultural mores
?
fixed moral attitudes or customs of a particular group; ethics based on these
Law and Ethics in Information Security
Legal, Ethical, and Professional Issues in Information Security
Cultural mores
? carry sanctions of a governing authority; ?? do not
Law and Ethics in Information Security
Legal, Ethical, and Professional Issues in Information Security
- Laws
- Ethics
?, ??, ???, ????, ?????
(5) Types of Law
Legal, Ethical, and Professional Issues in Information Security
- Civil
- Criminal
- Tort
- Private
- Public
?, ??, ???, ????, ?????, ??????
(6) Relevant U.S. Laws (General)
Legal, Ethical, and Professional Issues in Information Security
- Computer Fraud and Abuse Act of 1986 (CFA Act)
- National Information Infrastructure Protection Act of 1996
- USA Patriot Act of 2001
- Telecommunications Deregulation and Competition Act of 1996
- Communications Decency Act of 1996 (CDA)
- Computer Security Act of 1987
?
One of the hottest topics in information security
Legal, Ethical, and Professional Issues in Information Security
Privacy
?
Is a “state of being free from unsanctioned intrusion”
Legal, Ethical, and Professional Issues in Information Security
Privacy
?
Ability to aggregate data from multiple sources allows creation of information databases previously unheard of
Legal, Ethical, and Professional Issues in Information Security
Privacy
?
Ability to aggregate data from multiple sources allows creation of information databases previously unheard of
Legal, Ethical, and Professional Issues in Information Security
Privacy
?, ??, ???, ????, ?????
(5) Privacy of Customer Information
Legal, Ethical, and Professional Issues in Information Security
- Privacy of Customer Information Section of common carrier regulation
- Federal Privacy Act of 1974
- Electronic Communications Privacy Act of 1986
- Health Insurance Portability and Accountability Act of 1996 (HIPAA), aka Kennedy-Kassebaum Act
- Financial Services Modernization Act, or Gramm-Leach-Bliley Act of 1999
?, ??
(2) Export and Espionage Laws
Legal, Ethical, and Professional Issues in Information Security
- Economic Espionage Act of 1996 (EEA)
- Security And Freedom Through Encryption Act of 1999 (SAFE)
?, ??
Intellectual property recognized as protected asset in the U.S.; ?? extends to electronic formats
Legal, Ethical, and Professional Issues in Information Security
- U.S. Copyright Law
- copyright law
?
With proper acknowledgement, permissible to include portions of others’ work as reference
Legal, Ethical, and Professional Issues in Information Security
U.S. Copyright Law
?
Allows access to federal agency records or information not determined to be matter of national security
Legal, Ethical, and Professional Issues in Information Security
Freedom of Information Act of 1966 (FOIA)
?
U.S. government agencies required to disclose any requested information upon receipt of written request. Some information protected from disclosure
Legal, Ethical, and Professional Issues in Information Security
Freedom of Information Act of 1966 (FOIA)
?
Restrictions on organizational computer technology use exist at international, national, state, local levels
Legal, Ethical, and Professional Issues in Information Security
State and Local Regulations
? responsible for understanding state regulations and ensuring organization is compliant with regulations
State and Local Regulations
Legal, Ethical, and Professional Issues in Information Security
Information security professional
Establishes international task force overseeing Internet security functions for standardized international technology laws
International Laws and Legal Bodies
Legal, Ethical, and Professional Issues in Information Security
European Council Cyber-Crime Convention
Attempts to improve effectiveness of international investigations into breaches of technology law
International Laws and Legal Bodies
Legal, Ethical, and Professional Issues in Information Security
European Council Cyber-Crime Convention
Well received by intellectual property rights advocates due to emphasis on copyright infringement prosecution
International Laws and Legal Bodies
Legal, Ethical, and Professional Issues in Information Security
European Council Cyber-Crime Convention
Lacks realistic provisions for enforcement
International Laws and Legal Bodies
Legal, Ethical, and Professional Issues in Information Security
European Council Cyber-Crime Convention
U.S. contribution to international effort to reduce impact of copyright, trademark, and privacy infringement
Legal, Ethical, and Professional Issues in Information Security
Digital Millennium Copyright Act (DMCA)
A response to European Union Directive 95/46/EC, which adds protection to individuals with regard to processing and free movement of personal data
Legal, Ethical, and Professional Issues in Information Security
Digital Millennium Copyright Act (DMCA)
Makes provisions, to a degree, for information security during information warfare (IW)
Legal, Ethical, and Professional Issues in Information Security
United Nations Charter