0% found this document useful (0 votes)
6 views27 pages

Ethical Issues in IT Security

Uploaded by

yspor15
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views27 pages

Ethical Issues in IT Security

Uploaded by

yspor15
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Business Ethics 3e

• Khalidah Khalid Ali


• Zulkufly Ramly
• Lau Teck Chai

Business Ethics 3e | 9– 1
CHAPTER
9
Business Ethics and
Information Technology

Business Ethics 3e | 9– 2
Learning Outcomes

❑ Identify the underlying ethical and social issues in information technology


❑ Identify the various security threats of information systems
❑ Discuss some current ethical issues in information technology
❑ Explain how organisations can establish information system controls to
ensure better information system security
❑ Discuss the government’s role in managing information system security
❑ Distinguish and differentiate the different laws against cybercrime

All Rights Reserved © 2026 Business Ethics 3e | 9– 3


Introduction

❑ Information technology (IT) has provided much variety in terms of


available information and resources, as well as new prospects for
users, which in turn has given much needed understanding of ethics
in contemporary times.
❑ The risks posed by unethical adoption of IT have also increased in
tandem with the increase of IT acceptance in our everyday lives.
❑ However, the importance of ethics and human values have been
seriously undermined with dire consequences. Therefore, developing
and sharing IT guidelines are imperative as they could influence
individuals’ present and future practices.

All Rights Reserved © 2026 Business Ethics 3e | 9– 4


Overview of Ethical and Social
Concerns in Information Technology

❑ In business, information is seen as the means through which


organisations expand and increase their capacity to achieve their
goals. Therefore, information forms intellectual capital and
organisations value this capital as an important resource.
❑ There are many and varied ethical and social challenges in business,
in particular how data and information are collected, handled and
distributed.
❑ The main ethical and social concern is people’s fear of losing their
personal information, being used or made accessible to the public
without their consent. The ethical concerns that most organisations
face are related to privacy, accuracy, intellectual property and
accessibility.

All Rights Reserved © 2026 Business Ethics 3e | 9– 5


Overview of Ethical and Social
Concerns in Information Technology
(cont.)

❑ Privacy
– The main concern related to privacy is what kind of information
should people be required to divulge of themselves and under what
conditions should they do it?
– An array of technologies are available that could mitigate some of the
risks associated with privacy, including encryption,
anonymization/pseudonymization, and web browser interface
technologies that protect data from unauthorised access.
– The Malaysian government passed a bill in the Personal Data
Protection Act 2010 (PDPA) to regulate the processing of personal
data by data users in the context of commercial transactions that will
safeguard the personal data and interests of individuals.

All Rights Reserved © 2026 Business Ethics 3e | 9– 6


Overview of Ethical and Social
Concerns in Information Technology
(cont.)

❑ Accuracy
– Effective decision-making is driven by accurate information. Therefore,
organisations must ensure that the information disseminated across and
within the organisation is accurate.
– Ethical issues involving accuracy can be mitigated by determining the
basis for the level of accuracy in any given system and whether it is
sufficient.
– With the advancement of IT, organisations can now use automated data
entry systems that caution users of bad data entry, thus improving
accuracy.

All Rights Reserved © 2026 Business Ethics 3e | 9– 7


Overview of Ethical and Social
Concerns in Information Technology
(cont.)

❑ Intellectual Property
– Intellectual property rights have become the main concern of
organisations, especially the issues of intangible rights of ownership
in an asset such as a software programme.
– There are four types of intellectual property rights relevant to
software, i.e. patents, copyrights, trade secrets and trademarks.
❑ Accessibility
– The level of accessibility of information systems threatens to increase
the gap between the haves and the have-nots.
– In the long run, this gap may create social problems in the society.

All Rights Reserved © 2026 Business Ethics 3e | 9– 8


Security Threats that Affect
Information Systems

❑ Cybercrime
– Cybercrimes can be defined as ‘offences that are committed against
individuals or groups of individuals, with a criminal motive to
intentionally harm the reputation of the victim(s) or cause physical or
mental harm, or loss, to the victim(s) directly or indirectly using
modern telecommunication networks such as the Internet (including
but not limited to chat rooms, emails, noticeboards and groups) and
mobile phones (using Bluetooth, Short Message Service (SMS) or
Multimedia Messaging Service (MMS))’.
– Cybercrime covers a wide range of different attacks and shapes,
including theft of personal data, copyright infringement, fraud, child
pornography, cyberstalking and cyberbullying.

All Rights Reserved © 2026 Business Ethics 3e | 9– 9


Security Threats that Affect
Information Systems (cont.)

❑ Hacking and Cracking


– Hacking and cracking are malicious acts and related to security
threats from outside the organisation.
– Hackers are individuals who enjoy going into a system to understand
how the whole system works.
– Crackers are individuals who break into a system by cracking
passwords, spoofing and exploiting weaknesses found in the system.
❑ Computer Viruses
– Computer viruses that occur in the system can create nuisance, alter
or damage data, steal information, or cripple the system’s functions.

All Rights Reserved © 2026 Business Ethics 3e | 9– 10


Security Threats that Affect
Information Systems (cont.)

❑ Malware, Spyware and Adware


– Malware are malicious independent programmes that disguise
themselves as useful applications, and are able to capture private
information. Worms, logic bombs and Trojan horses are different
form of malware.
– Spyware is used to gather private personal information that is then
relayed to third parties that have vested interests in the information,
for example, advertisers.
– Adware is another form of computer programme that is malicious.
Advertisements such as pop-up windows or advertising banners on
web pages are one form of adware. The adware captures and reports
users’ habits, preferences or even personal information.

All Rights Reserved © 2026 Business Ethics 3e | 9– 11


Security Threats that Affect
Information Systems (cont.)

❑ Non-malicious Threats
– Threats to information systems security can also come from authorised
users who are not aware of their actions.
– Usually these threats come from the employees themselves, such as
data-entry clerks and system operators who are unfamiliar with the
system.
– Although actions by these employees are unintentional, they still
directly and indirectly contribute to security problems.
– Data-entry or programming errors can cause a system crash, which can
cause valuable data to be lost, damaged or altered, causing
organisations to operate at a loss.

All Rights Reserved © 2026 Business Ethics 3e | 9– 12


Security Threats that Affect
Information Systems (cont.)

❑ Spamming, Phishing and Spoofing


– Spam is any form of email message that contains copies of the same
message, and are forced on people that do not request or require the
message. Spamming is usually done by unauthorised individuals, who steal
Internet mails, scan Usenet postings or search addresses via the web.
– Phishing is also related to email messages that are forced onto its
recipients. However, it is more critical than spam as it is used to gather
personal and financial information disguised as legitimate emails.
– Spoofing refers to email messages that appear to have been sent from
someone other than the real sender with malicious intentions. Thus, the
emails cannot be traced back to the originator.

All Rights Reserved © 2026 Business Ethics 3e | 9– 13


Security Threats that Affect
Information Systems (cont.)

❑ Denial of Service, Abuse of Wireless Networks, Misuse of Public Web


Applications
– The difficulty to establish connections between servers and legitimate clients
is termed as denial of service (DoS). Hackers use this condition to their
advantage by hijacking and controlling thousands of computers remotely to
launch massive, coordinated attacks.
– The convenience and flexibility of wireless networks in providing data and
information is often abused by organisations or people, referred to as abuse
of wireless networks.
– The gaining of access to an organisation’s network and data by unauthorised
users disrupts the organisation’s activities. E-commerce applications over the
Internet can create vulnerability and abuse of this application.

All Rights Reserved © 2026 Business Ethics 3e | 9– 14


Security Threats that Affect
Information Systems (cont.)

❑ Computer Theft and Website Defacement


– Laptops and desktops are important artefacts of information systems
and need to be protected. The main security concern is that they
become the target for thieves.
– Theft of these items involve the loss of tangible and intangible assets.
– Organisations should also be concerned about their websites. One
security concern is website defacement, where the website is
sabotaged by a third party and the attackers take advantage of
undisclosed system vulnerabilities or unpatched systems.

All Rights Reserved © 2026 Business Ethics 3e | 9– 15


Current Ethical Issues in
Information Technology

❑ Consumer Privacy
❑ Employee/workplace Surveillance and Privacy
❑ Location Privacy
❑ Globalisation of Online Activity
❑ Protection of Intellectual Property

All Rights Reserved © 2026 Business Ethics 3e | 9– 16


Managing Information System
Security

❑ Quarantine Software
– Organisations can install quarantine software (i.e. anti-virus,
anti-adware and anti-spyware).
– By having effective access control and regularly updating the software
organisations can keep their computers free from viruses or malware.
❑ Operating System Penetration Software
– Several steps can be taken to guard against downloading free patches
offered by hackers and crackers, by installing several operating system
penetration software.
– Organisations can use the patch-management software by automating
the distribution of authentic patches from multiple software vendors.

All Rights Reserved © 2026 Business Ethics 3e | 9– 17


Managing Information System
Security (cont.)

❑ Security Policies and Procedure Initiatives


– Organisations need to design and implement information systems
security policies, procedures and initiatives, which should effectively
protect organisations against unauthorised access.
– The content of these policies should be on maintaining in-house and
off-site backup of corporate data, as well as include installing
software that can be quickly restored in the case of a system failure.

All Rights Reserved © 2026 Business Ethics 3e | 9– 18


Government’s Role in Managing
Information System Security

❑ There has been an increasing trend of cyberthreats and attacks


happening in Malaysia and around the world in the last few
years. The common forms of cyberattacks, which include
phishing, malware, ransomware, hacking and denial of
service (DoS) attacks, have been making headlines globally
and such threats could have a direct impact on Malaysian
companies.

All Rights Reserved © 2026 Business Ethics 3e | 9– 19


Government’s Role in Managing
Information System Security

❑ In order to set a clear legal framework in managing information system


security in Malaysia, the following provides the context;
❑ Generally, Articles 5, 9 and 13 of the Federal Constitution govern business
analytics.
❑ In Malaysia, information security system matters (privacy inclusive) and
offences are governed by the following legislations;
I. Personal Data Protection Act 2010 (PDPA)
II. Computer Crimes Act 1997 (CCA)
III. Communication and Multimedia Act 1998 (CMA)
IV. Intellectual Property laws including Copyright Act 1987
V. The Penal Code (covering crimes related to fraud, abetment,
impersonation, etc)

All Rights Reserved © 2026 Business Ethics 3e | 9– 20


Malaysia Introduces The Cyber
Security Act 2024

❑ Due to increasing cybersecurity threats, and in an attempt to enhance and


safeguard Malaysia’s cyber security landscape and infrastructure, the
Cyber Security Bill 2024 was approved by the Malaysian Parliament on
27 March 2024. The Cyber Security Act 2024 (the Act) or CSA has come
into force on 26 August 2024.

❑ The CSA establishes the National Cyber Security Committee ("NACSA")


as the relevant authority to implement and enforce its provisions.

All Rights Reserved © 2026 Business Ethics 3e | 9– 21


Protection Against Cybercrime:
Malaysian Legal Framework

❑ Hacking
– Under section 3 of the Computer Crimes Act 1997 (CCA), it is an offence if a person
knowingly and intentionally accesses a computer without authorisation (i.e. hacking) and
causes a computer to perform any function with the intent to secure access to any
programme or data held in any computer. Punishment: a fine not exceeding RM50, 000
or imprisonment not exceeding 5 years.
❑ Denial of Service Attacks
– Under section 233(1)(b) of the Communications and Multimedia Act 1998 (CMA), a
person who continuously, repeatedly or otherwise initiates a communication using any
application services with the intent to annoy, abuse, threaten or harass any person at any
numbered or electronic address commits an offence, regardless of whether the
communication ensued and whether or not the person initiating such communication
disclosed their identity. Punishment: a fine not exceeding RM50, 000 or imprisonment
not exceeding 1 year.
– The Cyber Security Act (CSA) 2024 further provides protection of victims against cyber
attacks and abuses/ harassments (For details, see Business Ethics 3e pp.298-299 ).

All Rights Reserved © 2026 Business Ethics 3e | 9– 22


Protection Against Cybercrime:
Malaysian Legal Framework (cont.)

❑ Phishing
– Under section 416 of the Malaysian Penal Code, any person is said to
‘cheat by personation’, if he cheats by pretending to be some other
person, or by knowingly substituting one person for another, or
representing that he or any other person is a person other than he or
such other person really is.
❑ Infection of IT Systems with Malware
– Under section 5 of the CCA, it is an offence for a person to commit any
act which he knows will cause unauthorised modification of the
contents of any computer.

All Rights Reserved © 2026 Business Ethics 3e | 9– 23


Protection Against Cybercrime:
Malaysian Legal Framework (cont.)

❑ Possession or Use of Hardware, Software or Other Tools to Commit


Cybercrime
– Under section 236 of the CMA, it is an offence for a person to possess
or use any counterfeit access devices, unauthorised access devices (e.g.
lost, stolen, expired or obtained with the intention to defraud), any
device-making equipment intended to make counterfeit access devices,
or any other equipment or device modified or altered or intended to
alter or modify such other equipment or device, in order to obtain
unauthorised access to any network services, etc.
– Under section 240 of the CMA, it is an offence to distribute or
advertise any communications equipment or device for interception of
communication.

All Rights Reserved © 2026 Business Ethics 3e | 9– 24


Protection Against Cybercrime:
Malaysian Legal Framework (cont.)

❑ Identity Theft/Identity Fraud


– Section 416 of the Penal Code may apply to identity theft (e.g. in
connection with access devices).
❑ Electronic Theft
– Section 41 of the Copyright Act sets out a range of offences for
copyright infringement, which include the making for sale or hire,
distributing, and exhibiting in public any infringing copy during the
subsistence of copyright in a work or performer’s right.

All Rights Reserved © 2026 Business Ethics 3e | 9– 25


Failure by an Organisation to
Implement Cybersecurity Measures

❑ With the promulgation of CSA in 2024, there is hence a legislation


which imposes a blanket requirement in respect of implementing
cybersecurity measures.
❑ Even the PDPA covers these provisions although it applies to
organisations involved in commercial transactions and expressly
excludes the Malaysian government.
❑ Organisations that are involved in processing personal data are
required to implement minimum security standards as prescribed by
the PDP Standards, or such other standards as prescribed by the
Personal Data Protection Commissioner (the PDP Commissioner)
from time to time.

All Rights Reserved © 2026 Business Ethics 3e | 9– 26


Failure by an Organisation to Implement
Cybersecurity Measures (cont.)

❑ Certain sectors are additionally subject to the guidelines requiring the


implementation of certain cybersecurity measures, for example:
❑ In the capital market industry, capital market entities are subject to
cybersecurity requirements as set out in the Guidelines on Management of
Cyber Risk issued by the Securities Commission of Malaysia (SC), and
❑ In the banking and financial sector, banks and financial institutions are
subject to the requirements as set out in the Guidelines on Management of
IT Environment (GPIS 1) issued by the Central Bank of Malaysia, i.e.,
Bank Negara Malaysia (BNM).
(Source: [Link] retrieved on 30 January, 2025)

All Rights Reserved © 2026 Business Ethics 3e | 9– 27

You might also like