0% found this document useful (0 votes)
8 views5 pages

Cybersecurity and Ethical Issues in IS

Chapter 5 discusses the critical role of information systems in business and society, highlighting the challenges posed by cybercrime, ethical dilemmas, and legal issues. It outlines various types of cybercrime, online safety measures, and ethical considerations surrounding privacy, accuracy, and accessibility. Additionally, it addresses legal frameworks like the Cybercrime Prevention Act and Data Privacy Act, as well as social issues such as the digital divide and misinformation.

Uploaded by

danteschuy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views5 pages

Cybersecurity and Ethical Issues in IS

Chapter 5 discusses the critical role of information systems in business and society, highlighting the challenges posed by cybercrime, ethical dilemmas, and legal issues. It outlines various types of cybercrime, online safety measures, and ethical considerations surrounding privacy, accuracy, and accessibility. Additionally, it addresses legal frameworks like the Cybercrime Prevention Act and Data Privacy Act, as well as social issues such as the digital divide and misinformation.

Uploaded by

danteschuy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter 5 - Information Systems in Business and Society

In the modern era of technology, information systems are essential to business processes and
societal operations. Yet, with greater dependence on technology comes great challenges such as
cyberattacks, ethical issues, social issues, and legal issues.

Cybercrime and Information System Security


A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt
digital life in general.
Cybercrime is criminal activity that either targets or uses a computer, a computer network or a
networked device.

Types of cybercrime:
 Phishing - an email sent from an internet. Criminal disguised as legitimate or trustworthy source.
The message is meant to lure you into revealing sensitive or confidential information, or by trying to
threaten you with legal repercussions if you don’t comply.
 Pharming – sends user to fake website instead of the real website the user intended to visit.
 Internet scam - usually, scammers will employ all sorts of tactics to deceive online users and trick
them into revealing sensitive information so that they can either steal their money or their identity.
 Malware - It is a malicious software disguised as real software often secretly installed, intended to
transfer and gather information like passwords without user’s permission.
o Ransomware – Blackmails you.
o Spyware – Steals your data
o Adware – Spams you with ads
o Worms – spread across computers
o Trojans – Sneak malware onto your PC
o Botnets – Turn your PC into a zombie
 Spamming or Spam - an unsolicited email, instant messages, or social media messages. These
are fairly easy to spot and can be damaging if you open or respond.

Online Safety Measures


1. Never give any personal information about yourself over the internet.
2. Never give any banking or sensitive information unless you are sure that it is a reputable business
having a secure device.
3. Never open any messages or attachment from someone you don’t know.
4. Regularly check your privacy settings in your account to make sure you are not sharing important
personal information.
5. When using a public computer terminal make sure to delete your browsing data before leaving.
6. Keep your software updated to avoid security holes.
7. Do not download or install software or anything on your computer or cell phone that is unknown to
you.

Ethical, Legal, and Social Issues of Information Systems

Ethical Issues in Information Systems:


Ethical issues arise when decisions about the development, use, and impact of IS involve
moral considerations. Key ethical challenges include:
 Privacy: The collection, storage, and use of personal data raise significant privacy
concerns. Individuals have a right to control their personal information, and IS
professionals have a responsibility to protect that right. This includes ensuring data
security, being transparent about data collection practices, and providing individuals with
control over how their data is used. Ethical dilemmas arise when the benefits of data
collection (e.g., personalized services) are weighed against the risks to privacy.

 Accuracy: The reliability and validity of information are crucial for ethical decision-making.
Inaccurate information can lead to unfair or discriminatory outcomes. IS professionals have
a responsibility to ensure the accuracy of data and to correct errors promptly. This includes
implementing data quality controls and validating data before it is used for decision-
making.

 Property: Protecting intellectual property rights and digital assets is essential for fostering
innovation and creativity. Copyright, patents, and trade secrets are legal mechanisms for
protecting intellectual property. However, the digital environment makes it easier to copy
and distribute digital content, raising ethical challenges related to piracy and plagiarism.

 Accessibility: Ensuring equitable access to information and technology is a matter of


social justice. The digital divide creates disparities in access to education, employment,
and other opportunities. IS professionals have a responsibility to design systems that are
accessible to everyone, regardless of their background or abilities.

 Intellectual Property: This encompasses copyrights, patents, trademarks, and trade


secrets. Ethical considerations include respecting intellectual property rights, avoiding
plagiarism, and ensuring that software and digital content are used legally. The ease of
copying and distributing digital content creates unique ethical challenges in this area.

Legal Issues in Information Systems


 Republic Act No. 10175 (Cybercrime Prevention Act of 2012)
 An act defining cybercrime, providing for the prevention, investigation, suppression and the
imposition of penalties therefor and for other purposes.
o Scope:
 Covers a wide range of cyber offenses, including:
 Cybersex, child pornography, and other online sexual offenses.
 Offenses against the confidentiality, integrity and availability of computer
data and systems.
 Computer-related forgery and fraud.
 Cyber-squatting and other domain name-related offenses.
 System interference and data damage.

 Republic Act No. 10173 (Data Privacy Act of 2012)


 An act protecting individual personal information in information and communications
systems in the government and the private sector, creating for this purpose a national
privacy commission, and for other purposes.
o Scope:
 Applies to any natural or juridical person involved in the processing of personal
information.
 Defines personal information as any information that can be used to identify an
individual.
 Establishes the rights of data subjects, including the right to access, correct, and
delete their personal data.

 Department of Information and Communications Technology (DICT) Circulars and


Guidelines
o Specific Examples:
 Guidelines on the protection of critical information infrastructure.
 Circulars on cybersecurity incident reporting.
 Standards for government websites and online services.
 Guidelines on the use of Cloud computing.

o Importance:
 These circulars and guidelines provide practical guidance on implementing
cybersecurity best practices.
 They are updated regularly to reflect the evolving threat landscape.
 IS professionals must stay informed of these updates.

 National Cybersecurity Plan


o Key Objectives:
 Strengthening the cybersecurity capabilities of the government and private sector.
 Protecting critical information infrastructure.
 Combating cybercrime.
 Promoting cybersecurity awareness.
 Fostering international cooperation.
o Implementation:
 The government is working to implement the plan through various initiatives and
programs.
 This includes capacity building, public-private partnerships, and international
collaboration.

Social Issues in Information Systems


 Digital Divide: The digital divide refers to the gap between those who have access to technology
and those who don't. This gap can create inequalities in access to education, employment,
healthcare, and other essential services. Bridging the digital divide is a crucial social challenge.

 Job Displacement: Automation and AI have the potential to displace workers in certain industries.
As machines take over routine tasks, workers may need to acquire new skills to remain competitive
in the job market. Addressing the potential for job displacement is a significant social and economic
challenge.

 Information Overload: The sheer volume of information available online can be overwhelming.
Individuals need to develop critical thinking skills to evaluate the credibility and accuracy of
information and to avoid being misled by misinformation or fake news.
 Social Isolation: While technology can connect people in some ways, excessive use of
technology can also lead to social isolation and loneliness. It's important to maintain a healthy
balance between online and offline interactions.

 Misinformation and Fake News: The rapid spread of misinformation and fake news through
social media poses a threat to democracy, public health, and social cohesion. Combating
misinformation and promoting media literacy are crucial social challenges.

 Privacy and Surveillance: The increasing use of surveillance technologies raises concerns about
privacy and civil liberties. Balancing security needs with individual rights is a complex social and
ethical challenge.

References:
Cybersecurity & Infrastructure Security Agency (CISA). (2023). kk. U.S. Department of Homeland
Security. [Link]
ENISA. (2023). Threat landscape 2023: Emerging cyber threats and trends. European Union Agency for
Cybersecurity. [Link]
Floridi, L. (2021). The ethics of artificial intelligence: Principles, challenges, and opportunities. Oxford
University Press.
Republic of the Philippines. (2012). Cybercrime Prevention Act of 2012 (Republic Act No. 10175). Official
Gazette. [Link]
Republic of the Philippines. (2012). Data Privacy Act of 2012 (Republic Act No. 10173). National Privacy
Commission. [Link]
Solove, D. J. (2023). The digital person: Technology and privacy in the information age (2nd ed.). NYU
Press.
UNESCO. (2023). Global education monitoring report: Technology in education—A tool on whose
terms? United Nations. [Link]
Van Dijk, J. (2020). The digital divide. Polity Press.
Verizon. (2024). 2024 Data breach investigations report (DBIR). Verizon
Business. [Link]

Common questions

Powered by AI

Organizations can address ethical challenges related to privacy in information systems by implementing several measures. They should ensure data security through robust cybersecurity practices, be transparent about their data collection and usage practices, and allow individuals control over their data. Specific measures include providing clear privacy policies, enabling users to access and correct their personal data, and using data only for stated purposes. Additionally, organizations should balance the benefits of data collection with privacy risks, ensuring that privacy is prioritized alongside organizational goals .

Job displacement due to automation and AI leads to social challenges by replacing jobs that require routine tasks, potentially increasing unemployment and economic inequality. To address this, measures such as reskilling and upskilling workers to equip them with new competencies required in the digital economy are necessary. Educational and training programs need to focus on emerging technologies and industries, while policies supporting workforce transition, such as job placement and financial incentives for affected individuals, can help mitigate these impacts .

To protect against cybercrime such as phishing and malware, individuals should avoid giving personal information over the internet, especially to unreputable sources, and not click on unknown email attachments or links. It's essential to keep privacy settings up-to-date and ensure that software, including antivirus programs, is regularly updated to patch security vulnerabilities. Using secure connections, especially when handling sensitive information, and being cautious with online interactions are also crucial .

Technology has contributed to social isolation by replacing face-to-face interactions with digital communications, which might lack depth or emotional richness. Users might engage more with virtual connections than physical ones, leading to feelings of loneliness. To mitigate this issue, it's important to encourage a balanced use of technology emphasizing the value of offline relationships and activities. Technology design focusing on facilitating meaningful interactions and promoting digital wellbeing is also crucial .

The Digital Divide refers to the gap between individuals who have access to technology and those who do not, creating disparities in social equity, especially in education and employment. Those without access to technology face significant barriers in education, as many learning resources and opportunities are increasingly online-based. This limits educational attainment and future job prospects, as many employment opportunities require digital literacy and experience with technology. Moreover, individuals lacking access to technology are at a disadvantage in the job market both in finding jobs and in acquiring new skills necessary for career advancement .

The National Cybersecurity Plan plays a pivotal role in strengthening cybersecurity by outlining strategies for enhancing the cybersecurity capabilities of both government and private entities. It focuses on protecting critical information infrastructure, combating cybercrime, and fostering cybersecurity awareness through initiatives such as capacity building and public-private partnerships. Additionally, the plan encourages international collaboration to address cybersecurity challenges comprehensively .

The Cybercrime Prevention Act provides a comprehensive legal framework to address and mitigate online threats by defining various cyber offenses, including cybersex, child pornography, computer-related forgery, and cyber-squatting. By setting penalties and defining measures for prevention and investigation, the Act strengthens law enforcement's ability to combat cybercrime. It applies to offenses against the confidentiality, integrity, and availability of computer systems, enhancing cyber resilience and protection for individuals and organizations .

Balancing the benefits of data collection, such as providing personalized services, with privacy risks, presents ethical dilemmas as organizations must weigh efficiency against individual rights. This requires establishing clear guidelines on data usage that prioritize transparency and user consent. Organizations can address these dilemmas by implementing privacy impact assessments, enhancing data minimization strategies, and involving stakeholders in policy discussions to ensure that privacy considerations are integrated into data-driven initiatives from the outset .

Cyberattacks compromise the integrity and functionality of information systems by disrupting services, stealing sensitive data, and causing financial or reputational harm. Attacks like phishing and malware infiltration can lead to unauthorized data access and system manipulations, affecting decision-making processes and altering data reliability. Ransomware holds critical data hostage, compromising system availability and potentially halting business operations. These attacks require organizations to invest significantly in cybersecurity measures to safeguard their information systems .

The key objectives of the National Cybersecurity Plan include enhancing the cybersecurity capabilities of government and private sectors, protecting critical information infrastructure, combating cybercrime, promoting cybersecurity awareness, and fostering international cooperation. Implementation of these objectives involves several initiatives such as building cybersecurity capacity, establishing public-private partnerships, and engaging in international collaboration to develop unified approaches against cyber threats. These efforts are aimed at improving national cyber resilience and preparedness .

You might also like