1 of 20

CHAPTER 3

Legal, Ethical, and

Professional Issues

in Information Security

"In civilized life, law floats in a sea of ethics."

— Earl Warren, Chief Justice, 1962

Principles of Information Security

6th Edition | Whitman & Mattord

2 of 20

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

Learning Objectives

01

Describe functions and relationships among laws, regulations, and professional organizations in information security

02

Explain the key differences between laws and ethics in the context of information security

03

Identify major national and international laws that affect the practice of information security

04

Discuss the role of privacy as it applies to law, ethics, and information security practice

3 of 20

Law and Ethics in Information Security

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

LAWS

Definition: Rules that mandate or prohibit certain behavior — enforced by the state��Authority: Carry the authority of a governing body��Consequences: Violations result in criminal/civil penalties, fines, or imprisonment��Examples: Computer Fraud & Abuse Act, HIPAA, FISMA, CFAA

VS

ETHICS

Definition: Branch of philosophy on moral judgment — socially accepted behavior��Authority: Based on cultural mores — NO state enforcement��Consequences: Social disapproval, professional censure, loss of certification��Examples: ACM Code of Ethics, (ISC)² Canons, Ten Commandments of Computer Ethics

4 of 20

Organizational Liability: Due Care & Due Diligence

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

DUE CARE

• Measures an organization takes to ensure EVERY employee knows what is acceptable and what is not

• Think: Policies, training, awareness programs

• Failure to exercise due care = INCREASED LIABILITY

DUE DILIGENCE

• Ongoing, reasonable steps to CONTINUOUSLY maintain the standard of due care

• Due care = acting ethically once

• Due diligence = proving compliance over time

• Never a one-time task — ongoing responsibility

Long-Arm Jurisdiction

Given the Internet's global reach, any court can assert authority over an individual or organization if it can establish jurisdiction — even across international borders. Cases are typically tried in the injured party's home area, which usually FAVORS the injured party.

5 of 20

Policy Versus Law: The 5 Enforceability Criteria

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

For a policy to be legally enforceable, ALL five conditions must be met:

01

Dissemination

(Distribution)

Policy made readily available — hard copy, electronic, intranet posting

02

Review

(Reading)

Distributed in intelligible form including alternate languages and recordings

03

Comprehension

(Understanding)

Employee understands the policy — tested via quizzes and assessments

04

Compliance

(Agreement)

Employee agreed to comply — logon banners, signed forms, or key acknowledgment

05

Uniform Enforcement

(Consistency)

Policy enforced consistently regardless of employee status or role

KEY: Unlike laws, ignorance of POLICY is an acceptable defense — so enforcement and communication are critical!

6 of 20

Types of Law in the United States

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

Constitutional Law

Origin: U.S. Constitution, state/local charter

Provides the fundamental framework. Includes Fourth Amendment protecting citizens from unlawful search and seizure — critical for digital forensics.

Statutory Law

Origin: Legislative branch (Congress)

Where most cybercrime laws come from — CFAA, HIPAA, FISMA, CAN-SPAM. Subcategories include Civil, Criminal, Private, and Public law.

Regulatory / Administrative Law

Origin: Executive branch / regulatory agencies

Executive orders and agency regulations. Examples: FCC regulations, HIPAA privacy rules, SEC requirements.

Common Law / Case Law

Origin: Judicial branch — court precedents

Interpretation of law based on prior court rulings. Shapes how cybercrime statutes are applied in practice.

Within Statutory Law: Civil (tort) • Criminal • Private • Public law

7 of 20

Key U.S. Privacy Laws

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

1974

Federal Privacy Act

Governs federal agency use of personal information. Holds agencies accountable for releasing private info without permission.

1986

ECPA (Wiretapping Act)

Regulates interception of wire, electronic, and oral communications. Works with the 4th Amendment.

1996

HIPAA

Protects healthcare data. Penalties up to $250K + 10 years. 5 fundamental principles including consumer control and data security.

1999

Gramm-Leach-Bliley Act

Financial institutions must disclose privacy policies on data sharing. Annual re-disclosure required. Customers can opt out.

2002

FISMA

All federal agencies must establish agency-wide InfoSec programs. 8 requirements including risk assessments, training, and annual testing.

2009

HITECH Act (HIPAA+)

Expands HIPAA to ALL business partners of healthcare orgs. Fines up to $1.5M/year. 60-day breach notification rule.

8 of 20

U.S. Information Security Law Timeline

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

1914 – FTCA

1974 – Privacy Act

1986 – CFAA + ECPA

1987 – Computer Security Act

1996 – HIPAA + Econ. Espionage

1997 – No Electronic Theft Act

1998 – DMCA + Identity Theft Act

1999 – GLB Act

2002 – SOX + FISMA

2003 – CAN-SPAM

2009 – HITECH Act

2014 – FISMA Modernization

2015 – USA FREEDOM Act

Other: FERPA, COPPA, ECPA, ITAR, Cybersecurity Workforce Act

Over 30 federal laws govern information security practice — professionals must stay current!

9 of 20

HIPAA & HITECH: Healthcare Data Protection Deep Dive

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

HIPAA – 5 Fundamental Principles

1

Consumer Control of medical information

2

Boundaries on the use of medical information

3

Accountability to maintain privacy of specified information types

4

Balance of public responsibility vs. impact to individual patients

5

Security of health information through technical & admin safeguards

HITECH Act (2009) — Key Changes

Expanded Coverage:

All HCO business partners (legal, accounting, IT firms) must comply with HIPAA as if they were HCOs

Higher Fines:

Up to $1.5 million per calendar year — significantly higher than original HIPAA

Private Right of Action:

Private citizens and lawyers can sue to collect fines for security breaches

60-Day Breach Notification:

Organizations have 60 days to notify affected individuals after a PHI breach

500+ Individual Breach:

Must notify Secretary of HHS AND major media outlets in the affected area

HHS Web Publication:

HHS publishes breach information publicly on its website

10 of 20

Identity Theft

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

17.6M

U.S. identity theft victims in 2014

(7% of all residents age 16+)

Personally Identifiable Information (PII):

Name • Address • Social Security Number

Family info • Employment history • Financial information

FTC's 4-Step Response for Identity Theft Victims:

01

Fraud Alert

Report to one of the 3 national credit reporting companies (Equifax, Experian, TransUnion)

02

Order Credit Reports

Initial fraud alert entitles you to free reports from all 3 agencies. Review for fraudulent activity.

03

Create ID Theft Report

File FTC complaint → identity theft affidavit → use to file police report and deal with creditors

04

Monitor Progress

Document ALL calls, letters, and communications throughout the resolution process

11 of 20

Copyright Law, Export Controls & Espionage Laws

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

U.S. Copyright Law & Fair Use

• Intellectual property is a protected asset in the U.S.

• Copyright Law (17 USC) covers published works including electronic formats

• Fair Use: Educational use allowed IF: for education/libraries, non-profit, not excessive, proper citation

• Works must not be represented as one's own (anti-plagiarism)

Digital Millennium Copyright Act (DMCA) 1998

• Prohibits CIRCUMVENTION of copy protection measures

• Bans manufacturing devices to bypass copy protection

• Bans trafficking in circumvention devices

• Prohibits altering copyright information embedded in works

• ISPs excluded from certain contributory infringement

Economic Espionage Act 1996

• Protects American IP and competitive advantage

• Prevents trade secrets from being illegally shared

• Strong criminal penalties for economic espionage

Security & Freedom Through Encryption Act 1999

• Right to use/sell encryption WITHOUT key registration (key escrow)

• Encryption use is NOT probable cause for criminal suspicion

• Relaxes export restrictions on encryption products

• Additional penalties for using encryption to commit a crime

12 of 20

International Laws & Legal Bodies

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

United Kingdom

• Computer Misuse Act 1990 — First major UK computer crime law

• Human Rights Act 1998 — Article 8: right to privacy

• Freedom of Information Act 2000 — public access to govt documents

• RIPA 2000 — regulates government interception of communications

Australia

• Privacy Act 1988 — 11 principles for public sector, 10 for private

• Telecommunications Act 1997 — data retention by ISPs

• Corporations Act 2001 — similar to SOX for financial reporting

• Spam Act 2003 — requires consent + unsubscribe mechanism

• Cybercrime Legislation Amendment Bill 2011 — aligns with EU Convention

Council of Europe Convention on Cybercrime 2001

• 41 nations ratified (incl. U.S. & U.K.) as of January 2014

• Standardizes technology laws across international borders

• Goal: simplify cross-border law enforcement cooperation

• Weakness: lacks realistic enforcement provisions

• WTO TRIPS Agreement (1994): first major international IP protection framework

13 of 20

Ethics and Information Security

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

Ten Commandments of Computer Ethics

1

Thou shalt not use a computer to harm other people

2

Thou shalt not interfere with other people's computer work

3

Thou shalt not snoop around in other people's computer files

4

Thou shalt not use a computer to steal

5

Thou shalt not use a computer to bear false witness

6

Thou shalt not copy or use proprietary software for which you have not paid

7

Thou shalt not use other people's computer resources without authorization

8

Thou shalt not appropriate other people's intellectual output

9

Thou shalt think about the social consequences of the systems you design

10

Thou shalt always use a computer with consideration for fellow humans

3 Causes of Unethical Behavior

Ignorance

Education is the primary deterrent — publish and train on policies and laws

Accident

Careful planning & access controls prevent accidental modifications

Intent

Technical controls + vigorous prosecution deter deliberate bad actors

3 Conditions for Effective Deterrence

01

Fear of Penalty: Threats of imprisonment or forfeiture more effective than verbal reprimand

02

Apprehension Risk: Offenders must believe there is a strong possibility of being caught

03

Penalty Applied: Offenders must believe the penalty WILL actually be administered

14 of 20

Ethical Differences Across Cultures — Global Software Piracy

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

Software Piracy

U.S. least tolerant. Netherlands most permissive. Singapore & Hong Kong showed moderate tolerance despite being labeled piracy hotbeds.

Illicit Use (Hacking)

All groups condemned hacking — but Singapore & Hong Kong more tolerant than U.S., Wales, England & Australia students.

Corporate Resources

Most cultures accept personal use of company computers UNLESS explicitly prohibited. Only Singapore & Hong Kong viewed it as unethical.

Total worldwide unlicensed software value in 2015:

$52.2 Billion

15 of 20

Codes of Ethics of Professional Organizations

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

ACM

Association of Computing Machinery

100,000+ members. 24 ethical imperatives. Promotes education, conferences, and the Communications of the ACM.

www.acm.org

(ISC)²

International InfoSec Certification Consortium

90,000+ certified (CISSP/SSCP). 4 Mandatory Canons: Protect society • Act honorably • Provide competent service • Advance the profession

www.isc2.org

SANS / GIAC

Global Information Assurance Certification

55,000+ certified. 4 focus areas: Security Admin, Security Mgmt, IT Audits, Software Security. Violation = certification loss.

www.giac.org

ISACA

Information Systems Audit & Control Association

110,000+ members. Focus on auditing, control, and security. CISA and CISM certifications.

www.isaca.org

ISSA

Information Systems Security Association

10,000+ members in 100+ countries. Mission: information exchange and educational development. Promotes CIA triad in management practices.

www.issa.org

Certification loss = reduced marketability and earning power — a powerful real-world deterrent!

16 of 20

Key U.S. Federal Agencies in Information Security

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

DHS

Dept. of Homeland Security

Created 2003 post-9/11. NPPD handles cyber threats. S&T is R&D arm. US-CERT is cyber incident response unit.

US-CERT

U.S. Computer Emergency Readiness Team

Division of DHS/NCCIC. Reports phishing, malware, software vulnerabilities. NICCS = cybersecurity career resource.

USSS

U.S. Secret Service

Relocated to DHS 2002. Protects financial infrastructure. Operation Firewall: 28 arrests across 7 countries.

FBI / IC3

Federal Bureau of Investigation

Primary law enforcement. Cyber Division investigates intrusions and identity theft. IC3 = cybercrime complaint clearinghouse (with NW3C).

InfraGard

FBI Public-Private Partnership

Est. 2001. 60+ regional chapters. Encrypted alert network. Shares threat intelligence between govt and private sector.

NSA / IAD

National Security Agency

Leads U.S. cryptology: SIGINT + Information Assurance. IAD = cyber defense solutions. NIETP = Centers of Excellence program for universities.

17 of 20

The National Security Agency (NSA) — Information Assurance Role

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

NSA Organizational Roles

SIGINT (Signals Intelligence)

Collection, analysis, and distribution of information from foreign communications networks for intelligence and counterintelligence purposes

Information Assurance (IA)

Guarantees confidentiality, integrity, and availability of information in storage, processing, and transmission — the government term for InfoSec

Information Assurance Directorate (IAD)

Provides InfoSec solutions: technologies, specifications, standards, operational doctrine, and cyber defense support

Common Criteria

A set of IAD standards designed to promote understanding of information security across government and commercial sectors

NIETP (National IA Education & Training Program)

Partners with DHS to recognize 'Centers of Excellence in Information Assurance/Cyber Defense' at universities

Privacy & Information Aggregation

Aggregate Information: Collective group data with personal identifiers REMOVED — acceptable for analytics��Information Aggregation: Combining non-private data from MULTIPLE sources to create private profiles — violates privacy

Clipper Chip Controversy

Proposed technology that used a 2-part encryption key managed by two separate government agencies. Designed to protect individual communications WHILE allowing government to decrypt suspect transmissions.

Result: NOT implemented due to privacy advocacy pressure.

18 of 20

FISMA — 8 Requirements for Federal Agency InfoSec Programs

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

Federal Information Security Management Act (2002): All federal agencies must develop, document, and implement an agency-wide information security program.

1

Periodic Risk Assessments

Assess risk and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction

2

Risk-Based Policies & Procedures

Cost-effectively reduce InfoSec risks to acceptable levels; address InfoSec throughout the system lifecycle

3

Subordinate Security Plans

Provide adequate InfoSec for networks, facilities, and system groups as appropriate

4

Security Awareness Training

Train all personnel including contractors on InfoSec risks associated with their activities

5

Annual Testing & Evaluation

Test effectiveness of InfoSec policies and controls — NO LESS THAN ANNUALLY — including management, operational, and technical controls

6

Remedial Action Process

Plan, implement, evaluate, and document remedial actions to address any policy or procedure deficiencies

7

Incident Response Procedures

Detect, report, and respond to security incidents; notify Federal InfoSec incident center; mitigate risks before substantial damage

8

Continuity of Operations

Plans and procedures to ensure continuity of operations for all information systems supporting agency operations

19 of 20

Chapter 3 Summary: Key Takeaways

Chapter 3 | Legal, Ethical & Professional Issues in InfoSec

1

Laws carry state authority; ethics are based on cultural mores. Key difference: enforcement by government vs. social norms.

2

Due care + due diligence reduce organizational liability. Both are required — care sets the standard, diligence maintains it.

3

Policies need 5 criteria to be enforceable: Dissemination, Review, Comprehension, Compliance, Uniform Enforcement.

4

30+ U.S. laws govern InfoSec — CFAA, HIPAA, FISMA, GLB, DMCA, CAN-SPAM, HITECH, Identity Theft Acts, and more.

5

Identity theft affects 17.6M Americans annually. FTC 4-step response: fraud alert, credit reports, ID theft report, monitor progress.

6

International laws (Council of Europe Convention, WTO TRIPS, DMCA, UK/Australia laws) attempt cross-border cooperation.

7

3 causes of unethical behavior: ignorance, accident, intent. 3 deterrence conditions: fear of penalty, apprehension risk, penalty applied.

8

ACM, (ISC)², SANS/GIAC, ISACA, ISSA all maintain ethical codes. Certification loss creates powerful real-world deterrence.

20 of 20

Discussion Questions

Q1

You find a flash drive at work containing sensitive company data and a payment note. What are your legal and ethical obligations? Who do you tell?

Q2

How do due care and due diligence work together? Give a scenario where an organization exercises one but not the other.

Q3

Your organization has a policy against personal use of company computers — but it's never been communicated to employees. Can the policy be enforced?

Q4

Should encryption be freely available to everyone, including criminals? How does the Security and Freedom Through Encryption Act address this tension?

Q5

Do you think certification codes of ethics are effective deterrents? Why or why not? What is the role of (ISC)², ISACA, and SANS?

Principles of Information Security, 6th Edition — Whitman & Mattord