CHAPTER 3
Legal, Ethical, and
Professional Issues
in Information Security
"In civilized life, law floats in a sea of ethics."
— Earl Warren, Chief Justice, 1962
Principles of Information Security
6th Edition | Whitman & Mattord
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
Learning Objectives
01
Describe functions and relationships among laws, regulations, and professional organizations in information security
02
Explain the key differences between laws and ethics in the context of information security
03
Identify major national and international laws that affect the practice of information security
04
Discuss the role of privacy as it applies to law, ethics, and information security practice
Law and Ethics in Information Security
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
LAWS
Definition: Rules that mandate or prohibit certain behavior — enforced by the state��Authority: Carry the authority of a governing body��Consequences: Violations result in criminal/civil penalties, fines, or imprisonment��Examples: Computer Fraud & Abuse Act, HIPAA, FISMA, CFAA
VS
ETHICS
Definition: Branch of philosophy on moral judgment — socially accepted behavior��Authority: Based on cultural mores — NO state enforcement��Consequences: Social disapproval, professional censure, loss of certification��Examples: ACM Code of Ethics, (ISC)² Canons, Ten Commandments of Computer Ethics
Organizational Liability: Due Care & Due Diligence
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
DUE CARE
• Measures an organization takes to ensure EVERY employee knows what is acceptable and what is not
• Think: Policies, training, awareness programs
• Failure to exercise due care = INCREASED LIABILITY
DUE DILIGENCE
• Ongoing, reasonable steps to CONTINUOUSLY maintain the standard of due care
• Due care = acting ethically once
• Due diligence = proving compliance over time
• Never a one-time task — ongoing responsibility
Long-Arm Jurisdiction
Given the Internet's global reach, any court can assert authority over an individual or organization if it can establish jurisdiction — even across international borders. Cases are typically tried in the injured party's home area, which usually FAVORS the injured party.
Policy Versus Law: The 5 Enforceability Criteria
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
For a policy to be legally enforceable, ALL five conditions must be met:
01
Dissemination
(Distribution)
Policy made readily available — hard copy, electronic, intranet posting
02
Review
(Reading)
Distributed in intelligible form including alternate languages and recordings
03
Comprehension
(Understanding)
Employee understands the policy — tested via quizzes and assessments
04
Compliance
(Agreement)
Employee agreed to comply — logon banners, signed forms, or key acknowledgment
05
Uniform Enforcement
(Consistency)
Policy enforced consistently regardless of employee status or role
KEY: Unlike laws, ignorance of POLICY is an acceptable defense — so enforcement and communication are critical!
Types of Law in the United States
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
Constitutional Law
Origin: U.S. Constitution, state/local charter
Provides the fundamental framework. Includes Fourth Amendment protecting citizens from unlawful search and seizure — critical for digital forensics.
Statutory Law
Origin: Legislative branch (Congress)
Where most cybercrime laws come from — CFAA, HIPAA, FISMA, CAN-SPAM. Subcategories include Civil, Criminal, Private, and Public law.
Regulatory / Administrative Law
Origin: Executive branch / regulatory agencies
Executive orders and agency regulations. Examples: FCC regulations, HIPAA privacy rules, SEC requirements.
Common Law / Case Law
Origin: Judicial branch — court precedents
Interpretation of law based on prior court rulings. Shapes how cybercrime statutes are applied in practice.
Within Statutory Law: Civil (tort) • Criminal • Private • Public law
Key U.S. Privacy Laws
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
1974
Federal Privacy Act
Governs federal agency use of personal information. Holds agencies accountable for releasing private info without permission.
1986
ECPA (Wiretapping Act)
Regulates interception of wire, electronic, and oral communications. Works with the 4th Amendment.
1996
HIPAA
Protects healthcare data. Penalties up to $250K + 10 years. 5 fundamental principles including consumer control and data security.
1999
Gramm-Leach-Bliley Act
Financial institutions must disclose privacy policies on data sharing. Annual re-disclosure required. Customers can opt out.
2002
FISMA
All federal agencies must establish agency-wide InfoSec programs. 8 requirements including risk assessments, training, and annual testing.
2009
HITECH Act (HIPAA+)
Expands HIPAA to ALL business partners of healthcare orgs. Fines up to $1.5M/year. 60-day breach notification rule.
U.S. Information Security Law Timeline
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
1914 – FTCA
1974 – Privacy Act
1986 – CFAA + ECPA
1987 – Computer Security Act
1996 – HIPAA + Econ. Espionage
1997 – No Electronic Theft Act
1998 – DMCA + Identity Theft Act
1999 – GLB Act
2002 – SOX + FISMA
2003 – CAN-SPAM
2009 – HITECH Act
2014 – FISMA Modernization
2015 – USA FREEDOM Act
Other: FERPA, COPPA, ECPA, ITAR, Cybersecurity Workforce Act
Over 30 federal laws govern information security practice — professionals must stay current!
HIPAA & HITECH: Healthcare Data Protection Deep Dive
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
HIPAA – 5 Fundamental Principles
1
Consumer Control of medical information
2
Boundaries on the use of medical information
3
Accountability to maintain privacy of specified information types
4
Balance of public responsibility vs. impact to individual patients
5
Security of health information through technical & admin safeguards
HITECH Act (2009) — Key Changes
Expanded Coverage:
All HCO business partners (legal, accounting, IT firms) must comply with HIPAA as if they were HCOs
Higher Fines:
Up to $1.5 million per calendar year — significantly higher than original HIPAA
Private Right of Action:
Private citizens and lawyers can sue to collect fines for security breaches
60-Day Breach Notification:
Organizations have 60 days to notify affected individuals after a PHI breach
500+ Individual Breach:
Must notify Secretary of HHS AND major media outlets in the affected area
HHS Web Publication:
HHS publishes breach information publicly on its website
Identity Theft
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
17.6M
U.S. identity theft victims in 2014
(7% of all residents age 16+)
Personally Identifiable Information (PII):
Name • Address • Social Security Number
Family info • Employment history • Financial information
FTC's 4-Step Response for Identity Theft Victims:
01
Fraud Alert
Report to one of the 3 national credit reporting companies (Equifax, Experian, TransUnion)
02
Order Credit Reports
Initial fraud alert entitles you to free reports from all 3 agencies. Review for fraudulent activity.
03
Create ID Theft Report
File FTC complaint → identity theft affidavit → use to file police report and deal with creditors
04
Monitor Progress
Document ALL calls, letters, and communications throughout the resolution process
Copyright Law, Export Controls & Espionage Laws
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
U.S. Copyright Law & Fair Use
• Intellectual property is a protected asset in the U.S.
• Copyright Law (17 USC) covers published works including electronic formats
• Fair Use: Educational use allowed IF: for education/libraries, non-profit, not excessive, proper citation
• Works must not be represented as one's own (anti-plagiarism)
Digital Millennium Copyright Act (DMCA) 1998
• Prohibits CIRCUMVENTION of copy protection measures
• Bans manufacturing devices to bypass copy protection
• Bans trafficking in circumvention devices
• Prohibits altering copyright information embedded in works
• ISPs excluded from certain contributory infringement
Economic Espionage Act 1996
• Protects American IP and competitive advantage
• Prevents trade secrets from being illegally shared
• Strong criminal penalties for economic espionage
Security & Freedom Through Encryption Act 1999
• Right to use/sell encryption WITHOUT key registration (key escrow)
• Encryption use is NOT probable cause for criminal suspicion
• Relaxes export restrictions on encryption products
• Additional penalties for using encryption to commit a crime
International Laws & Legal Bodies
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
United Kingdom
• Computer Misuse Act 1990 — First major UK computer crime law
• Human Rights Act 1998 — Article 8: right to privacy
• Freedom of Information Act 2000 — public access to govt documents
• RIPA 2000 — regulates government interception of communications
Australia
• Privacy Act 1988 — 11 principles for public sector, 10 for private
• Telecommunications Act 1997 — data retention by ISPs
• Corporations Act 2001 — similar to SOX for financial reporting
• Spam Act 2003 — requires consent + unsubscribe mechanism
• Cybercrime Legislation Amendment Bill 2011 — aligns with EU Convention
Council of Europe Convention on Cybercrime 2001
• 41 nations ratified (incl. U.S. & U.K.) as of January 2014
• Standardizes technology laws across international borders
• Goal: simplify cross-border law enforcement cooperation
• Weakness: lacks realistic enforcement provisions
• WTO TRIPS Agreement (1994): first major international IP protection framework
Ethics and Information Security
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
Ten Commandments of Computer Ethics
1
Thou shalt not use a computer to harm other people
2
Thou shalt not interfere with other people's computer work
3
Thou shalt not snoop around in other people's computer files
4
Thou shalt not use a computer to steal
5
Thou shalt not use a computer to bear false witness
6
Thou shalt not copy or use proprietary software for which you have not paid
7
Thou shalt not use other people's computer resources without authorization
8
Thou shalt not appropriate other people's intellectual output
9
Thou shalt think about the social consequences of the systems you design
10
Thou shalt always use a computer with consideration for fellow humans
3 Causes of Unethical Behavior
Ignorance
Education is the primary deterrent — publish and train on policies and laws
Accident
Careful planning & access controls prevent accidental modifications
Intent
Technical controls + vigorous prosecution deter deliberate bad actors
3 Conditions for Effective Deterrence
01
Fear of Penalty: Threats of imprisonment or forfeiture more effective than verbal reprimand
02
Apprehension Risk: Offenders must believe there is a strong possibility of being caught
03
Penalty Applied: Offenders must believe the penalty WILL actually be administered
Ethical Differences Across Cultures — Global Software Piracy
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
Software Piracy
U.S. least tolerant. Netherlands most permissive. Singapore & Hong Kong showed moderate tolerance despite being labeled piracy hotbeds.
Illicit Use (Hacking)
All groups condemned hacking — but Singapore & Hong Kong more tolerant than U.S., Wales, England & Australia students.
Corporate Resources
Most cultures accept personal use of company computers UNLESS explicitly prohibited. Only Singapore & Hong Kong viewed it as unethical.
Total worldwide unlicensed software value in 2015:
$52.2 Billion
Codes of Ethics of Professional Organizations
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
ACM
Association of Computing Machinery
100,000+ members. 24 ethical imperatives. Promotes education, conferences, and the Communications of the ACM.
www.acm.org
(ISC)²
International InfoSec Certification Consortium
90,000+ certified (CISSP/SSCP). 4 Mandatory Canons: Protect society • Act honorably • Provide competent service • Advance the profession
www.isc2.org
SANS / GIAC
Global Information Assurance Certification
55,000+ certified. 4 focus areas: Security Admin, Security Mgmt, IT Audits, Software Security. Violation = certification loss.
www.giac.org
ISACA
Information Systems Audit & Control Association
110,000+ members. Focus on auditing, control, and security. CISA and CISM certifications.
www.isaca.org
ISSA
Information Systems Security Association
10,000+ members in 100+ countries. Mission: information exchange and educational development. Promotes CIA triad in management practices.
www.issa.org
Certification loss = reduced marketability and earning power — a powerful real-world deterrent!
Key U.S. Federal Agencies in Information Security
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
DHS
Dept. of Homeland Security
Created 2003 post-9/11. NPPD handles cyber threats. S&T is R&D arm. US-CERT is cyber incident response unit.
US-CERT
U.S. Computer Emergency Readiness Team
Division of DHS/NCCIC. Reports phishing, malware, software vulnerabilities. NICCS = cybersecurity career resource.
USSS
U.S. Secret Service
Relocated to DHS 2002. Protects financial infrastructure. Operation Firewall: 28 arrests across 7 countries.
FBI / IC3
Federal Bureau of Investigation
Primary law enforcement. Cyber Division investigates intrusions and identity theft. IC3 = cybercrime complaint clearinghouse (with NW3C).
InfraGard
FBI Public-Private Partnership
Est. 2001. 60+ regional chapters. Encrypted alert network. Shares threat intelligence between govt and private sector.
NSA / IAD
National Security Agency
Leads U.S. cryptology: SIGINT + Information Assurance. IAD = cyber defense solutions. NIETP = Centers of Excellence program for universities.
The National Security Agency (NSA) — Information Assurance Role
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
NSA Organizational Roles
SIGINT (Signals Intelligence)
Collection, analysis, and distribution of information from foreign communications networks for intelligence and counterintelligence purposes
Information Assurance (IA)
Guarantees confidentiality, integrity, and availability of information in storage, processing, and transmission — the government term for InfoSec
Information Assurance Directorate (IAD)
Provides InfoSec solutions: technologies, specifications, standards, operational doctrine, and cyber defense support
Common Criteria
A set of IAD standards designed to promote understanding of information security across government and commercial sectors
NIETP (National IA Education & Training Program)
Partners with DHS to recognize 'Centers of Excellence in Information Assurance/Cyber Defense' at universities
Privacy & Information Aggregation
Aggregate Information: Collective group data with personal identifiers REMOVED — acceptable for analytics��Information Aggregation: Combining non-private data from MULTIPLE sources to create private profiles — violates privacy
Clipper Chip Controversy
Proposed technology that used a 2-part encryption key managed by two separate government agencies. Designed to protect individual communications WHILE allowing government to decrypt suspect transmissions.
Result: NOT implemented due to privacy advocacy pressure.
FISMA — 8 Requirements for Federal Agency InfoSec Programs
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
Federal Information Security Management Act (2002): All federal agencies must develop, document, and implement an agency-wide information security program.
1
Periodic Risk Assessments
Assess risk and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction
2
Risk-Based Policies & Procedures
Cost-effectively reduce InfoSec risks to acceptable levels; address InfoSec throughout the system lifecycle
3
Subordinate Security Plans
Provide adequate InfoSec for networks, facilities, and system groups as appropriate
4
Security Awareness Training
Train all personnel including contractors on InfoSec risks associated with their activities
5
Annual Testing & Evaluation
Test effectiveness of InfoSec policies and controls — NO LESS THAN ANNUALLY — including management, operational, and technical controls
6
Remedial Action Process
Plan, implement, evaluate, and document remedial actions to address any policy or procedure deficiencies
7
Incident Response Procedures
Detect, report, and respond to security incidents; notify Federal InfoSec incident center; mitigate risks before substantial damage
8
Continuity of Operations
Plans and procedures to ensure continuity of operations for all information systems supporting agency operations
Chapter 3 Summary: Key Takeaways
Chapter 3 | Legal, Ethical & Professional Issues in InfoSec
1
Laws carry state authority; ethics are based on cultural mores. Key difference: enforcement by government vs. social norms.
2
Due care + due diligence reduce organizational liability. Both are required — care sets the standard, diligence maintains it.
3
Policies need 5 criteria to be enforceable: Dissemination, Review, Comprehension, Compliance, Uniform Enforcement.
4
30+ U.S. laws govern InfoSec — CFAA, HIPAA, FISMA, GLB, DMCA, CAN-SPAM, HITECH, Identity Theft Acts, and more.
5
Identity theft affects 17.6M Americans annually. FTC 4-step response: fraud alert, credit reports, ID theft report, monitor progress.
6
International laws (Council of Europe Convention, WTO TRIPS, DMCA, UK/Australia laws) attempt cross-border cooperation.
7
3 causes of unethical behavior: ignorance, accident, intent. 3 deterrence conditions: fear of penalty, apprehension risk, penalty applied.
8
ACM, (ISC)², SANS/GIAC, ISACA, ISSA all maintain ethical codes. Certification loss creates powerful real-world deterrence.
Discussion Questions
Q1
You find a flash drive at work containing sensitive company data and a payment note. What are your legal and ethical obligations? Who do you tell?
Q2
How do due care and due diligence work together? Give a scenario where an organization exercises one but not the other.
Q3
Your organization has a policy against personal use of company computers — but it's never been communicated to employees. Can the policy be enforced?
Q4
Should encryption be freely available to everyone, including criminals? How does the Security and Freedom Through Encryption Act address this tension?
Q5
Do you think certification codes of ethics are effective deterrents? Why or why not? What is the role of (ISC)², ISACA, and SANS?
Principles of Information Security, 6th Edition — Whitman & Mattord