0% found this document useful (0 votes)
12 views8 pages

Privacy and Surveillance in the Workplace

The document covers three key lessons in information systems: privacy, confidentiality, and workplace surveillance; intellectual property rights and digital resource management; and cybersecurity threats and ethical hacking. It emphasizes the importance of protecting employee data, understanding intellectual property in the digital age, and the responsibilities of individuals and organizations in maintaining cybersecurity. Each lesson outlines definitions, key concepts, and ethical considerations relevant to the topics discussed.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views8 pages

Privacy and Surveillance in the Workplace

The document covers three key lessons in information systems: privacy, confidentiality, and workplace surveillance; intellectual property rights and digital resource management; and cybersecurity threats and ethical hacking. It emphasizes the importance of protecting employee data, understanding intellectual property in the digital age, and the responsibilities of individuals and organizations in maintaining cybersecurity. Each lesson outlines definitions, key concepts, and ethical considerations relevant to the topics discussed.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

PROFESSIONAL ISSUES IN INFORMATION SYSTEM

IS 102 Course Module – Midterm


Lesson 1: Privacy, Confidentiality, and Workplace Surveillance

Intended Learning Outcomes (ILOs):


By the end of this module, students should be able to:

1. Define and differentiate privacy, confidentiality, and workplace surveillance.

2. Explain the importance of protecting employee data and organizational


information.

3. Analyze the ethical and legal implications of workplace surveillance practices.

4. Apply concepts of privacy and confidentiality in workplace scenarios through critical


thinking activities.

Introduction

In today’s digital age, the workplace is becoming increasingly data-driven. Employers collect,
store, and sometimes monitor employee activities for productivity, security, and compliance
purposes. While these practices may improve efficiency and protect organizational assets, they
also raise significant ethical and legal concerns regarding privacy and confidentiality.

This module will explore the key concepts of privacy, confidentiality, and workplace
surveillance, their interconnections, and their implications for both employees and employers.

Lesson Content / Key Concepts

1. Privacy

• Definition: The right of individuals to control access to their personal information and to
be free from unwarranted intrusion.

• Workplace Context: Employees expect some level of personal privacy (e.g., emails,
phone calls, restrooms, personal belongings).

• Example: An employee’s medical records must not be disclosed without consent.

2. Confidentiality

• Definition: The duty to keep sensitive information secure and only share it with
authorized individuals.

• Workplace Context: Employers and employees must handle company records, client
data, and employee files responsibly.
• Example: An HR officer must not share an employee’s salary details with unauthorized
staff.

3. Workplace Surveillance

• Definition: Monitoring of employees’ activities, communications, or behaviors using


technology or other means.

• Types:

o Electronic Monitoring: Emails, internet usage, keystroke logging.

o Video Surveillance: CCTV in offices or warehouses.

o Biometric Tracking: Fingerprint or facial recognition for attendance.

o GPS Tracking: Monitoring company vehicles.

• Purpose: Enhance productivity, prevent data breaches, ensure safety, reduce theft.

• Concerns: Can lead to employee stress, mistrust, and possible violations of personal
privacy.

• Example: Monitoring call center employees’ phone conversations to ensure quality


service.

4. Balancing Privacy, Confidentiality, and Surveillance


• Organizations must balance the need to protect their assets and maintain productivity
with respecting employees’ rights.

• Policies should:
o Be transparent and clearly communicated.

o Comply with labor laws and data protection regulations.

o Respect boundaries (e.g., not monitoring personal devices during breaks).

Summary

• Privacy is about an individual’s right to personal space and control over their
information.

• Confidentiality involves safeguarding sensitive data and ensuring it is not shared


inappropriately.

• Workplace surveillance is the monitoring of employee activities to ensure compliance,


security, and productivity.
• Employers must strike a balance between monitoring for legitimate business purposes
and respecting employee rights.

• Ethical and legal considerations play a critical role in implementing workplace


surveillance policies.

References

1. Westin, A. (1967). Privacy and Freedom. New York: Atheneum.

2. Smith, H. J., Dinev, T., & Xu, H. (2011). "Information Privacy Research: An
Interdisciplinary Review." MIS Quarterly.

3. European Union. (2018). General Data Protection Regulation (GDPR).

4. Philippine Data Privacy Act of 2012 (Republic Act No. 10173).

5. Ciocchetti, C. (2011). "The eavesdropping employer: A twenty-first century framework for


employee monitoring." American Business Law Journal.

Lesson 2: Intellectual Property Rights and Digital Resource Management

Intended Learning Outcomes (ILOs):

By the end of this module, students should be able to:

1. Define intellectual property rights (IPR) and explain their importance in the digital age.
2. Identify and differentiate types of intellectual property (copyright, patent, trademark,
trade secret).

3. Understand the role of digital resource management in protecting and using digital
content responsibly.

4. Apply ethical and legal considerations of IPR to real-life workplace and academic
scenarios.

Introduction

The digital era has transformed how information and creative works are produced, shared, and
consumed. With the ease of copying and distributing digital materials, intellectual property
rights (IPR) have become more important than ever. IPR ensures that creators, inventors, and
organizations retain ownership and recognition for their work, while also fostering innovation
and fair use.

At the same time, organizations must practice effective digital resource management—the
responsible use, storage, and protection of digital content. This module examines how IPR and
digital resource management work together to ensure ethical, legal, and secure handling of
knowledge and creativity.
Lesson Content / Key Concepts

1. Intellectual Property Rights (IPR)

• Definition: Legal protections given to creators or owners of works that result from
human creativity and innovation.

• Purpose: Safeguard ownership, encourage innovation, prevent unauthorized use or


theft.

• Types of IPR:

1. Copyright – Protects literary, artistic, and digital works (e.g., books, music,
software).

▪ Example: Downloading movies from a pirated site violates copyright.

2. Patent – Grants exclusive rights to inventors for a new product, process, or


design.

▪ Example: A company patents a new smartphone technology.

3. Trademark – Protects brand names, logos, or slogans that identify


goods/services.

▪ Example: Nike’s swoosh logo and “Just Do It” tagline.

4. Trade Secret – Protects confidential business information that gives a


competitive edge.

▪ Example: Coca-Cola’s secret formula.

2. Importance of IPR in the Digital Age

• Prevents plagiarism, piracy, and illegal reproduction of digital works.

• Provides creators and companies with recognition and financial benefits.

• Encourages continuous innovation in technology, media, and business.

• Builds trust between consumers and businesses.

3. Digital Resource Management

• Definition: The systematic process of organizing, storing, protecting, and ensuring


proper use of digital assets (data, documents, software, media).

• Key Principles:
1. Access Control – Only authorized users should access sensitive digital files.
2. Data Backup & Security – Protecting digital resources from loss, theft, or cyber-
attacks.

3. Proper Licensing – Using only legally acquired software, e-books, or media.


4. Ethical Use – Respecting copyright and avoiding plagiarism.

• Example: An educational institution using licensed software (MS Office, Turnitin) to


support teaching and research while preventing academic dishonesty.

4. Relationship Between IPR and Digital Resource Management

• IPR ensures creators’ rights, while digital resource management enforces responsible
use.

• Organizations need both to:

o Protect their assets.

o Maintain compliance with laws.


o Build an ethical culture in handling digital information.

Summary
• Intellectual Property Rights (IPR) protect creative and innovative works, ensuring
recognition and fairness for creators.
• IPR includes copyright, patents, trademarks, and trade secrets.

• Digital Resource Management focuses on the ethical and secure use of digital assets
through access control, licensing, and data protection.
• Together, IPR and digital resource management promote responsible innovation,
prevent digital theft, and ensure organizational integrity.

References

1. WIPO (World Intellectual Property Organization). (2023). Understanding Intellectual


Property. Retrieved from [Link]

2. Republic Act No. 8293 – Intellectual Property Code of the Philippines.

3. Lessig, L. (2004). Free Culture: How Big Media Uses Technology and the Law to Lock
Down Culture and Control Creativity. Penguin.
4. Association of Research Libraries. (2020). Digital Rights Management and Libraries.

5. European Union Intellectual Property Office (EUIPO). (2022). Guide on Trademarks and
Copyright in the Digital Economy.
Lesson 3: Cybersecurity Threats, Ethical Hacking, and Responsibilities
Intended Learning Outcomes (ILOs):

By the end of this module, students should be able to:

1. Define and explain cybersecurity threats and their impact on individuals, organizations,
and society.

2. Understand the concept of ethical hacking and how it differs from malicious hacking.

3. Identify the responsibilities of individuals and organizations in ensuring


cybersecurity.

4. Apply concepts by analyzing real-life cases and proposing preventive strategies.

Introduction

As the world becomes increasingly dependent on digital technology, threats to information


systems and online safety have multiplied. Cybersecurity is no longer optional; it is a necessity
for both organizations and individuals. Every day, cybercriminals exploit vulnerabilities to steal
data, disrupt services, or cause financial and reputational harm.

At the same time, ethical hacking has emerged as a professional practice to strengthen
cybersecurity by testing systems for weaknesses—legally and responsibly. However, with these
advancements come responsibilities: individuals and organizations must adopt ethical and legal
practices to safeguard data, respect privacy, and comply with cybersecurity regulations.
This module explores cybersecurity threats, ethical hacking, and responsibilities, providing
students with knowledge of risks, prevention strategies, and professional conduct in the digital
era.

Lesson Content / Key Concepts

1. Cybersecurity Threats

• Definition: Malicious acts or risks that compromise the integrity, confidentiality, or


availability of digital systems.

• Common Threats:
1. Malware – Viruses, worms, ransomware, spyware.

▪ Example: Ransomware encrypts files and demands payment for


decryption.

2. Phishing – Fraudulent emails or websites tricking users into revealing sensitive


information.
▪ Example: Fake banking email asking for login credentials.
3. Denial-of-Service (DoS/DDoS) Attacks – Overloading servers to disrupt
service.

▪ Example: Attackers flooding an e-commerce website with traffic until it


crashes.

4. Social Engineering – Manipulating people into disclosing confidential data.


▪ Example: An attacker posing as IT staff to gain system access.

5. Insider Threats – Employees misusing their access to harm the organization.

▪ Example: A disgruntled employee leaking confidential data.

2. Ethical Hacking

• Definition: Authorized practice of testing computer systems, applications, and networks


to find security vulnerabilities before malicious hackers exploit them.

• Ethical Hackers vs. Malicious Hackers:


o Ethical Hackers (White Hat): Work with permission, follow laws, improve
security.

o Malicious Hackers (Black Hat): Unauthorized access, theft, and damage for
personal gain.

o Gray Hat Hackers: Operate between the two; may expose vulnerabilities without
authorization but not always for malicious intent.

• Example: A company hires ethical hackers to perform penetration testing on its e-


commerce website to find security gaps before launching.

3. Responsibilities in Cybersecurity

• For Individuals:

o Use strong, unique passwords.

o Avoid suspicious links and downloads.

o Keep devices and software updated.

o Respect others’ privacy online.

• For Organizations:

o Implement firewalls, antivirus, and intrusion detection systems.

o Provide cybersecurity training for employees.


o Comply with data protection laws (e.g., GDPR, Data Privacy Act).
o Establish incident response and recovery plans.
• For Ethical Hackers:

o Always obtain legal permission before testing systems.

o Report vulnerabilities responsibly.


o Adhere to professional codes of ethics.

Summary
• Cybersecurity threats include malware, phishing, DDoS attacks, social engineering,
and insider threats.

• Ethical hacking is a legitimate practice that strengthens system defenses by identifying


vulnerabilities.

• Responsibilities in cybersecurity rest with individuals, organizations, and ethical


hackers alike. Everyone must follow ethical and legal standards to protect data and
systems.

• By balancing vigilance, prevention, and ethical conduct, organizations can defend


against cyber threats while maintaining trust and security in the digital world.

References
1. Stallings, W. (2019). Effective Cybersecurity: A Guide to Using Best Practices and
Standards. Pearson.

2. EC-Council. (2022). Certified Ethical Hacker (CEH) Study Guide.

3. Anderson, R. (2020). Security Engineering: A Guide to Building Dependable Distributed


Systems. Wiley.

4. Philippine Data Privacy Act of 2012 (RA 10173).

5. National Institute of Standards and Technology (NIST). (2021). Cybersecurity


Framework.

You might also like