0% found this document useful (0 votes)
15 views7 pages

Module 3 Case

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views7 pages

Module 3 Case

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Making and Enforcing 1

Running Head: Making and Enforcing Security Legislations and Standards

TUI UNIVERSITY

Module 3 – Case

Course #: ITM517

Information Security Overview for Managers and Policy Makers


Making and Enforcing 2

Introduction

Information security is the protection of information from a wide range of threats in

order to ensure business continuity, minimize business risk, and maximize return on

investments and business opportunities (ISO, 2010). Organizations and government often try

to achieve information security by establishing information security legislations and

standards. Making these legislations and standards however, is very challenging and often

times they do not achieve their objectives. This paper begins with an overview of some of the

major legislations and standards in information security, flowered by a discussion on whether

or not they are serving their purposes and then it discusses how the legislations may be

enforced and concludes with a discussion on how to establish security rules and regulations.

Major Legislations and Standards in Information Security: There are two

possibilities for defining the term “computer crime”: (1) the use of a computer by a criminal

to conduct illegal activity or (2) a computer as the target of illegal activity (Robinson, 2003).

In an attempt to address these two facets of computer crime, congress has instituted Federal

legislation regulating criminal activity involving information technology, including: The

Computer Fraud and Abuse Act; The Digital Millennium Copyright Act; The Electronic

Communications Protection Act; The Anticybersquatting Consumer Protection Act; The

CAN-SPAM Act, and The Communications Decency Act (Veitch, 2006). This paper will

describe three from the list.

The Digital Millennium Copyright Act (DMCA) amended several pre-existing sections of

Copyright Law. IT criminalizes the circumvention of any technology that controls access to a

copyrighted work (Robinson, 2003). Circumvention is defined as any attempt to descramble,

decrypt, avoid or impair a technological measure without authority—individual authority may be


Making and Enforcing 3

granted for reverse engineering for interoperability, encryption research, or security testing

(Veitch, 2006).

The Electronic Communications Protection Act of 1986 (ECPA) amended the previously

existing Wiretap Act, Sections 2510-22 of Title 18 of the United States Code, and created the

Stored Communications Act, Sections 2701-12 of Title 18 of the United States Code. The

essential purpose of the ECPA is to prohibit unauthorized or unjustified interception, disclosure,

or use of any communication, including electronic communication (Robinson, 2003).

In December 2003, U.S. President George W. Bush signed into law the Controlling the

Assault of Non-Solicited Pornography and Marketing Act of 2003 (S.877), more commonly referred

to as the CAN-SPAM Act of 2003 (Griam, 2003). The intent of this Act is to set specifications for

how email advertisers can legally distribute unsolicited commercial email (UCE) messages and

specifically commercial email messages containing pornographic text and images (Griam, 2003).

Along with the security legislations, there are also standards that are put in place with the aim

of attaining information security. These standards, BS7799, BS ISO/IEC17799: 2000 and its latest

version ISO/IEC 17799:2005 in particular, have been praised as being the keystone in any

successful information security management activities (Siponen, 2006). These standards establish

guidelines and general principles for initiating, implementing, maintaining, and improving

information security management in an organization (ISO, 2010).

Are these Legislations and Standards Serving their Purposes? The aim of these

legislations and standards is to achieve information security. But are they doing that? After the

CAN-SPAM Act was signed into law, a study was done to assess the compliance level. Based on

the study the level of compliance with the Act was low. The results of this study clearly indicates

that compliance with the CAN-SPAM Act six months after its enactment was very low with only

14.3% of email messages meeting even the minimum standards of compliance listed in this study
Making and Enforcing 4

(Grimes, 2003). Two years after the enactment of CAN-SPAM the overall compliance rate was down

even further to only 5.7% (Grimes, 2003).

As for the ISO standards they focus on ensuring that certain information security processes or

activities exist, while they are unconcerned about and fail to give advice on how these security

processes can be accomplished in practice (Siponen, 2006). Information security management

standards are primarily concerned with ensuring the existence of processes rather than the content of

these processes. These standards do not pay attention to an organization’s content problem, rather

they are more concerned with ensuring certain information security activities exist in organizations

and are less interested in how well they are done (Siponen, 2006). Also these processes, guidelines,

and the principles provided by the standards are abstract and simplified, and do not provide advice on

how the desired results are to be achieved in practice (Siponen, 2006). In other words these

standards by themselves will not achieve information security. However, organizations should

use them as a guideline in addressing their unique security content problem.

How should these legislations and standards be enforced? Enforcing these legislations

and standards are by no means an easy task. This interconnected computing age and the boom of

wireless computing makes it difficult to track the offenders, and not because something is printed

in law as illegal means that people will avoid doing it. Legislation for example, will not stop a

hacker from breaking the ECPA. Therefore an organization should not rest assure that the

legislations are in place and believe that is enough. Based on the CAN-SPAM survey it is clear

that government has its hands full in trying to enforce these legislations. This therefore means

that organizations should take it a step further if they are to obtain effective information security.

Organizations should first educate its staff about these legislations and put polices and

procedures in place that will avoid its employees, customers and other stakeholders from

breaking them. A marketing department for example may endorse a non-spam policy. On the
Making and Enforcing 5

other hand organizations should report any evidence of an offender who is disregarding the

legislations. If an organization for example reports an incident of the CFAA and the intruder is

arrested, this will alert other prospective intruders to be skeptic of trying to launch an attack on

such organization.

Enforcing the standards as outlined by the ISO is also not a clear cut task. Organizations

however, should try to observe such standards by breaking them down into daily operational

security activities. The BS ISO/IEC17799: 2000 suggests that, employees should follow security

producers correctly, and the standard implies that producing an introduction to information security

awareness programs (education and training activities) is the way to ensure this ( Siponen, 2006).

However, the standard does not suggest how users should be trained or motivated to follow

information security procedures, this is the duty of the organization since all organizations are

unique.

Establishing Security Rules and Regulations: It would be easy if an organization could

simply use the legislations and standards as a guideline in establishing information security rules

and regulations. However it is not that simple when you consider the political complexity (the

people, power struggles, hidden agendas and related nonsense that make up the average

business) that exists in many organizations. Establishing rules and regulations is clearly a

political task. Without compromising the security of an organization, law makers should be

sensitive to the organization’s political landscape when making security rules and regulations. In

information security decision making, law makers she ensure to include all the people with clout

in the organization to assist in establishing these laws. When such individuals are involve in

establishing these laws they will feel the need to be more involve in their enforcement. With

such potent individuals helping to enforce the laws their implementation has a greater chance of

succeeding.
Making and Enforcing 6

Conclusion

Several legislations and standards have been put in place with the aim of improving

information security—some by private organizations and others by the Federal government.

These legislations and standards however, are often challenging to enforce, hence they do not

achieve their objectives. Criminalizing an activity is simply not enough. Not because something

is signed into law as illegal means that individuals will refrain from doing it. Action must be

taken against offenders and be publicized as an example to prevent others from doing it.

Standards such as BS ISO/IEC17799: 2000 should be used as a guideline to develop and implement

organizations’ unique security model. In order to effectively develop and implement information

security rules and standards in an organization, one has to apply positive organizational politics.
Making and Enforcing 7

Reference

Grimes, G. (2007) Compliance with the CAN-SPAM Act of 2003. Communications of the

ACM, Vol. 50 Issue 2, p56-62. Retrieved February 16, 2010 from TUI library.

19, 2008 from TUI library.


ISO. (2010). ISO/IEC 17799:2005 Information technology - Security techniques - Code of

practice for information security management. Retrieved February 16, 2010 from

[Link]
widely_used_standards_other/information_security.htm

Robinson, S. (2003). U.S. Information Security Law, Part 3. Retrieved February 15, 2010, from

[Link]

Robinson, S. (2003). U.S. Information Security Law, Part Four. Retrieved February 15, 2010,

from [Link]

Robinson, S. (2003) U.S. Information Security Law, Part 2. Retrieved February 15, 2010, from

[Link]
Siponen, M. (2006). Information security standards focus on the existence of process, not its

content. Communications of the ACM, Vol. 49 Issue 8, pp. 97-100. Retrieved February

Veitch, C. (2006). INFORMATION SECURITY LAW:Federal Legislation and Recent Legal

Cases. New Mexico Institute of Mining and Technology Socorro, New Mexico.

Retrieved February 15, 2010 form

[Link]

You might also like