Chapter 4 - Ethics and Security
1. Explain the ethical issues surrounding information technology.
2. Describe a situation involving technology that is ethical but illegal.
Enron – directors drastically overstating profits which lead to the collapse of multi billion dollar costing the jobs of thousands of people and those affected downstream.
3. Describe and explain one of the computer use policies that a company might employee.
An ethical computer policy contains general principles to guide computer user behaviour, ex: ethical computer policy might explicitly state that users should refrain from playing computer games at work.
4. What are the 5 main technology security risks?
The five main security risks are:
- Human Error= Not Malicious, by Humans
- Natural Disasters= Floods, Earthquakes, Terrorist Attack
- Technical Failures= Software Bugs, Hardware Crashes
- Deliberate Acts= Sabotage, White Collar Crimes
- Management Failure= Lack of Procedure, Documentation, Training
5. Outline one way to reduce each risk.
- Human error – create an information security plan that details the various information security policies. A detailed information security plan can alleviate people-based information security issues.
- Natural disasters – use off off-site backups or storage to retrieve data that may be lost during a natural disaster
- Technical failures – can be minimised through content filtering which occurs when organisations use software that filters content to prevent the transmission of unauthorised information.'
- Deliberate acts – use of firewall which guards a private network by analysing the information leaving and entering the network
- Management failure – by training management and ensuring that all employees are up to date with system changes
6. What is a disaster recovery plan, what strategies might a firm employee?
A disaster recovery plan looks at those situations that prevent you from carrying on business. Careful planning helps your business get back to normal operations as quickly as possible. Strategies may include:
- Offsite backups
- Training programs for staff
- Appropriate backup procedures implemented into the business
No comments:
Post a Comment