Case One
Pretend that you are an employee of that company and that it is your job to speak with the CEO about the security breach. What would you say to him? Why?
I would inform the CEO on the dangers that might arise because of the security breach. These dangers include manipulation of the organization’s data by malicious hackers, invasion by outside users, overcrowding of the internet system thus affecting its operation, and danger or threat in relation to personal information about the company. I would also advice the CEO on the need to ensure security of the organization’s data. This is vital in order to maintain the reputation or image of the company within the market and the industry. It is also important to reduce elements of malicious hacking aimed at destroying the company. It is also ideal for the organization to train its personnel on the need and importance of recovery tools in case of breaches to the security like in the case study. This is ideal towards prevention and elimination of security breaches thus ensuring safety of the organization’s data. The training on the use of recovery tools would supplement handling of the hardware and software programs within the organization. I would also advice the CEO on the need to ensure safety of the network as the initial step towards elimination or reduction of security breaches within the company.
I would also advice the CEO on the need for protection due to increase in the attacks against information security in the modern world. It is crucial to note that no system is safe against attacks. The CEO needs to understand that it is a difficult task to defend against the attacks. The CEO would understand the reasons behind difficulty in defending attacks such as connection to internet, speed of the attacks, sophistication of the threats, simplicity of invasion, and faster rate in relation to detection against vulnerability by the attackers. Other reasons might include delays in the patching process, poor distribution of patch, and confusion of the users.
What recommendation would you make for training and awareness for the company?
I would recommend implementation of two approaches towards the security of the company from future breaches. The approaches would need to operate together in order to increase the effectiveness and efficiency in handling the security measures for the organization. The first approach would entail accurate and effective software and hardware security with reference to the organization’s data. The organization needs to adopt firewalls, secure connections, servers that have the capacity to verify users, and other precaution measures to ensure the security of the company’s information against future breaches. These attempts would enable the organization to limit interference from outside intruders or hackers into the system.
The organization should also adopt and implement effective programs to act as recovery tools. These recovery tools would offer accurate means of monitoring invasion or network traffic thus providing essential security to the company’s data. The second method or approach is much crucial in comparison to the first one. The organization should focus on the human factor while ensuring the security of its data and other relevant information from outside invasion. Studies show that the best security systems prove to be useless in the absence of qualified or trained personnel. The staff should undergo extensive training to understand on how to handle and operate the software and equipment. To ensure that this training is effective and efficient, it is ideal for the workforce to understand and grasp the application of the recovery tools in handling security breaches in the future.
Case Two
Where should the line be drawn on GPS tracking—or should there be a line at all?
There is need to draw a line on the GPS tracking when it comes to personal life. The person under the watch has the right to know that he or she is under the watch by the law enforcement in relation to implementation of the GPS devices. GPS devices are common in modern society with the aim of offering accurate and valuable information on the where about of individuals and the movements across the nations. It is ideal for the law enforcement agencies to notify the person under the watch on the aspect of GPS. All people have the right to privacy thus implementation of GPS devices without the knowledge of the individual in the context. For instance, parents should notify their children on the element of GPS to monitor their whereabouts in order to reduce invasion of privacy. Other aspects that do not hinder the right to privacy but offer threat to the public such as tracking of the criminals within the society should be under critical implementation of GPS. This would enhance the level of security within the society through effective and efficient application of GPS devices. GPS should utilize situations that relate to terrorism suspects, sex offenders or parolees, monitoring of employees, convenience purposes, and provision of care. This is an indication that the authority should draw the line on the private life while implementing the technological tracking devices in relation to the citizens.
Should authorities be able to monitor the location of individuals without their knowledge? What are the risks and the rewards?
It is unethical to monitor the location of individuals without their knowledge through the implementation of GPS technology. This is because of invasion of the right to privacy by the individuals under the watch of the law enforcement agencies. Individuals have the right to privacy thus the authority has to acquire warrant in order to spy on the person with his or her knowledge on the technological tracking device. Implementation of GPS in the modern organizations might be beneficial to the employer in relation to identification of liabilities within the setting of the business entity. This would enable the employer to track the performance of the worker within the working hours to ensure improvement and active participation towards the achievement of the goals and objectives of the organization. However, implementation of the device with extension to non-working hours would be risky with reference to the morale of the employees. Employees have the right to privacy like other common citizens. This calls for respecting the personal life of the individuals under the watch hence the authority need to notify an individual before adopting the use of GPS in order to track their movements. The authority might also have the lead in relation to criminal activity by tracking an individual without his or her knowledge since the person would conduct the business normally. In most case, the authority acquires invaluable information that has minimal influence in relation to public affairs hence non-beneficial to the society.
If you were to speak next at the panel discussion, what would you say?
I would acknowledge the fact that individuals have the right to privacy, and the use of technology should not limit the essence of their rights. This indicates that the authority should observe individuals’ right to privacy in the process of implementing technology track them in the search for valuable criminal information. I would recommend implementation of the tracking device (GPS) with the knowledge of the individual in order to limit unethical invasion of privacy. Individuals should have knowledge on the monitoring process through application of GPS technology. I would also elaborate on the need to draw the line while applying the influence of GPS by the authorities. Private matters should be out of equation thus the need for adoption of the bill describing on how to implement GPS effectively and efficiently by the law enforcers.
Case Three
Would the ability to hijack accounts violate federal wiretapping laws?
The legality of hijacking accounts has always occurred as a divisive issue with people having different views. The proposing side asserts that the use of Firesheep does not violate the wiretapping laws while the critics have it differently. However, the proposing side may have it right, just before the dispute settlement in courts, since Firesheep is a form of software. Everybody has the right of creating software provided it helps the individual run his or her computer world. It should not be another party’s business minding on which software the other people are using in their computers. The owners of the computer have the right of facilitating the way they are operating their computers. For instance, an individual should not view Firesheep as illegal since it help users to identify the other users on the public Wi-Fi hot spot who are visiting the unsecured Web site. Consequently, this allows the user to manage how thers (on the same Wi-Fi hot spot) are using the internet. Accessing the way other people are using their private accounts is also of much importance for security reasons. It keeps track for those using the social media to plan for their malicious activities apart from restricting them from accessing the unsecured web site.
The reasoning by the critics that the use of Firesheep will change innocent people into criminals does not consider the importance of the software to the world. The only question that is appropriate for the existence of Firesheep should be whether it is legal to access other parties’ account without their permission. Apart from this question, the use of the software should be legal since it has much effect on increasing the security within any given locality. The notion for the establishment of Firesheep was to increase knowledge regarding sites that do not have encryption for all traffic occurring between users and services provided by Web. Further, there is no recognizable federal prosecution, which has occurred on the personality creating software for log in into other people’s account. The question should not be on the legality of creation but on the users of the software.
Are the researchers making software that enables unauthorized access to other users’ accounts doing so with the intention of facilitating that crime? Or because they are not actively engaged in committing a crime, should they not be prosecuted?
The researchers involved in the creation of software normally have the notion of establishing something that will complement the use of computers in the world. Computer world is subject to inventions especially in the quest to adapt to the changing technology and the needs of the users. Consequently, the researchers’ creation of software that allows the unauthorized access to other users account should not be a subject to accreditation as a crime. First, use of the software is a trust owned by the users; hence, they should not face prosecution because of executing their trust. The use of the software also allows the user to detect the security threats associated with the Web sites. This makes the creation of the software act as a step of eliminating the security flaw, something that the Web sites had always ignored. Detecting what other people are accessing helps in tracking those individuals planning for their malicious activities through the Web sites. From the reasoning, the researchers should not be a subject to prosecution since they have valuable intentions (exposing security flaw) towards the creation of the software.
Case Four
How would you handle the situation?
The organization subjects the members into restriction of installing their application software to eliminate any suspicion of external attack on the system. Restriction of the installation of application software is valuable for every organization especially when it comes to ensuring security against possible viruses and malwares. My position as a technical support team makes me to the purpose for the security of the organization system. Consequently, I would not have to apply efforts in trying to go against the policy of the organization since the restriction facilitates the manageability and integrity of the system. Trying to remove the restrictions will be against the rules of the organization because it is obvious that all members will require the elimination of the restriction on them. I would have to tell them about the importance of software restriction policies to the running of the organization and the subsequent effects of lacking the restrictions. I would tell them that the removal of the restrictions would make the organization’s system a subject to effects of unreliability besides lacking proper manageability. Their stay within the organization forces the users to act within the restriction policies of the organization, which does not allow them installing any form of software application. The members should realize that installation of any software should be in line with the policies provided by the organization. Any member that may insist for the removal of restriction policy on him or her should have permission from the top management. This will ensure that the organization maintain the security of their system while ensuring the reliability of the member users.
What’s the best way to make users aware of a policy like this?
The best way of making the users aware of the restriction policy is through informing them about the importance of using the restrictive policy in the system. The top management should take the initiative of orienting the members about improving the integrity and manageability of the system. The management should inform the members that free system without restriction would provide the opportunity for the malicious script to invade the systems thereby paralyzing the running of the computer system. Apart from the orientation about the importance of the restrictive policy, the organization should teach the users on how they can work comfortably within the restrictions. This will help the users in adopting ways of staying far from the malicious contents. The only way to stay far from the malicious contents is through adopting the restrictive policies on software applications. The management should also educate the members on the importance of restrictive policy basing their views on the presence chains of computers. The presence of chains of computers always makes it easy for a malicious content to transfer from one user to another making them be more vulnerable to computer failure. This will trigger the user into adapting to the software restriction policy provided by the company since it is the only option to avoid the effect of malwares.
