Legal and Ethical Issues in InfoSec
Legal and Ethical Issues in InfoSec
[Link]
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 1
Module Objectives
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 3
Law and Ethics in Information Security
• Laws: rules that mandate or prohibit certain behavior and are enforced by the
state.
• Ethics: regulate and define socially acceptable behavior.
• Cultural mores: fixed moral attitudes or customs of a particular group.
• Laws carry the authority of a governing authority; ethics do not.
• Liability: the legal obligation of an entity extending beyond criminal or contract
law; includes the legal obligation to make restitution.
• Restitution: the legal obligation to compensate an injured party for wrongs
committed.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 4
Organizational Liability and the Need for
Counsel
• Jurisdiction: court’s right to hear a case if the wrong was committed in its
territory or involved its citizenry.
• Long-arm jurisdiction: application of laws to those residing outside a court’s
normal jurisdiction; usually granted when a person acts illegally within the
jurisdiction and leaves.
• Due care: the legal standard requiring a prudent organization to act legally and
ethically and know the consequences of actions.
• Due diligence: the legal standard requiring a prudent organization to maintain
the standard of due care and ensure actions are effective.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 5
Policy Versus Law (1 of 2)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 6
Policy Versus Law (2 of 2)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 7
Knowledge Check Activity 1
Business policies function as _____ laws and must be crafted and implemented
with care to ensure they are complete, appropriate, and fairly applied to everyone.
a. national
b. state
c. organizational
d. city
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 8
Knowledge Check Activity 1: Answer
Business policies function as _____ laws and must be crafted and implemented
with care to ensure they are complete, appropriate, and fairly applied to everyone.
Answer: c. organizational
Explanation.
Business polices are not directly aligned with criminal or civil laws although they
must be aligned with them. Policies are the rules inside the business.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 9
Types of Law
• Constitutional
• Statutory
− Civil
Tort
− Criminal
• Regulatory or Administrative
• Common, Case and Precedent
• Private vs Public
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 10
Relevant U.S. Laws
• The United States has been a leader in the development and implementation of
information security legislation.
• Information security legislation contributes to a more reliable business
environment and a stable economy.
• The United States has demonstrated understanding of the importance of
securing information and has specified penalties for individuals and
organizations that breach civil and criminal law.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 11
General Computer Crime Laws (1 of 3)
• Computer Fraud and Abuse Act of 1986 (CFA Act): Cornerstone of many computer-
related federal laws and enforcement efforts.
• National Information Infrastructure Protection Act of 1996:
‒ Modified several sections of the previous act and increased the penalties for
selected crimes.
‒ Severity of the penalties was judged on the value of the information and the
purpose, for example:
For purposes of commercial advantage.
For private financial gain.
In furtherance of a criminal act.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 12
General Computer Crime Laws (2 of 3)
• USA PATRIOT Act of 2001 provides law enforcement agencies with broader
latitude in order to combat terrorism-related activities.
• USA PATRIOT Improvement and Reauthorization Act made permanent fourteen
of the sixteen expanded powers of the Department of Homeland Security and
the FBI in investigating terrorist activity.
• USA FREEDOM Act inherited select USA PATRIOT functions as the PATRIOT
act expired in 2015.
• Computer Security Act of 1987 is one of the first attempts to protect federal
computer systems by establishing minimum acceptable security practices.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 13
General Computer Crime Laws (3 of 3)
[Link] laws-and-regulations/laws/fisma
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 14
Privacy (1 of 2)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 15
Information Aggregation
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 16
Privacy (2 of 2)
• U.S. Regulations
‒ Privacy of Customer Information Section of the common carrier regulation
‒ Federal Privacy Act of 1974
‒ Electronic Communications Privacy Act of 1986
‒ Health Insurance Portability and Accountability Act of 1996 (HIPAA), aka
Kennedy-Kassebaum Act
‒ Financial Services Modernization Act, or Gramm-Leach-Bliley Act of 1999
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 17
Knowledge Check Activity 2
Which of the following is another name for the Financial Services Modernization
Act?
a. Gramm-Leach-Bliley Act
b. Hitech Act
c. The HIPAA Act
d. Kennedy-Kassebaum Act
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 18
Knowledge Check Activity 2: Answer
Which of the following is another name for the Financial Services Modernization Act?
a. Gramm-Leach-Bliley Act
b. Hitech Act
c. The HIPAA Act
d. Kennedy-Kassebaum Act
Explanation.
The other choices are all healthcare-related privacy statutes.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 19
Identity Theft (1 of 2)
• Identity theft can occur when someone steals victim’s personally identifiable
information (PII) and poses as the victim to conduct actions/make purchases.
• Federal Trade Commission oversees efforts to foster coordination, effective
prosecution of criminals, and methods to increase victim’s restitution.
• Fraud and Related Activity in Connection with Identification Documents,
Authentication Features, and Information (Title 18, U.S.C. § 1028).
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 20
Identity Theft (2 of 2)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 22
U.S. Copyright Law
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 23
Knowledge Check Activity 3
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 24
Knowledge Check Activity 3: Answer
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 25
Financial Reporting
• Sarbanes-Oxley Act of 2002, also known as SOX or the Corporate and Auditing
Accountability and Responsibility Act of 2002, is a critical piece of legislation that
affects the executive management of publicly traded corporations and public
accounting firms.
• SOX seeks to improve the reliability and accuracy of financial reporting and
increase the accountability of corporate governance in publicly traded
companies.
• It provides penalties for noncompliance ranging from fines to jail terms.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 26
Freedom of Information Act of 1966 (FOIA)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 27
Payment Card Industry Data Security
Standards (PCI DSS)
• PCI Security Standards Council offers a standard of performance to which
organizations processing payment cards must comply.
‒ PCI DSS was developed to encourage and enhance cardholder data security
and facilitate the broad adoption of consistent data security measures globally.
‒ PCI DSS provides a baseline of technical and operational requirements
designed to protect account data.
‒ PCI DSS applies to all entities involved in payment card processing, including
merchants, processors, acquirers, issuers, and service providers.
‒ PCI DSS also applies to all other entities that store, process, or transmit
cardholder data (CHD) and/or sensitive authentication data (SAD).
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 28
PCI DSS Requirements (1 of 2)
Build and maintain a secure network Install and maintain a firewall configuration to protect cardholder data.
and systems Do not use vendor-supplied defaults for system passwords and other
security parameters.
Protect cardholder data Protect stored cardholder data.
Encrypt transmission of card holder data across open, public networks.
Maintain a vulnerability Protect all systems against malware and regularly update antivirus
management program software or programs.
Develop and maintain secure systems and applications.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 29
PCI DSS Requirements (2 of 2)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 30
State and Local Regulations
• Federal computer laws are mainly written specifically for federal information
systems; they have little applicability to private organizations.
• Information security professionals are responsible for understanding state
regulations and ensuring that organization is in compliance with regulations.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 31
International Laws and Legal Bodies
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 32
Council of Europe Convention on Cybercrime
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 33
WTO and the Agreement on Trade-Related
Aspects of IP Rights
• The first significant international effort to protect intellectual property rights
which outlines requirements for governmental oversight and legislation providing
minimum levels of protection for intellectual property.
• Agreement covers five issues:
− Application of basic principles of trading system and international intellectual
property agreements.
− Giving adequate protection to intellectual property rights.
− Enforcement of those rights by countries within their borders.
− Settling intellectual property disputes.
− Transitional arrangements while a new system is being introduced.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 34
Digital Millennium Copyright Act (DMCA)
• U.S. contribution to international effort to reduce impact of copyright, trademark, and privacy
infringement.
• A response to European Union Directive 95/46/EC states the following:
− Prohibits the circumvention of protections and countermeasures implemented by copyright
owners to control access to protected content.
− Prohibits the manufacture of devices to circumvent protections and countermeasures that
control access to protected content.
− Bans trafficking in devices manufactured to circumvent protections and countermeasures
that control access to protected content.
− Prohibits the altering of information attached or embedded into copyrighted material.
− Excludes Internet service providers from certain forms of contributory copyright
infringementExcludes ISPs from some copyright infringement.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 35
Ethics and Information Security
• Many professional disciplines have explicit rules governing the ethical behavior
of members.
• IT and InfoSec do not have binding codes of ethics.
• Professional associations and certification agencies work to maintain ethical
codes of conduct.
− Can prescribe ethical conduct
− Do not always have the ability to ban violators from practice in field
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 36
The Ten Commandments of Computer Ethics:
The Computer Ethics Institute
1. Thou shalt not use a computer to harm other people.
2. Thou shalt not interfere with other people’s computer work.
3. Thou shalt not snoop around in other people’s computer files.
4. Thou shalt not use a computer to steal.
5. Thou shalt not use a computer to bear false witness.
6. Thou shalt not copy or use proprietary software for which you have not paid.
7. Thou shalt not use other people’s computer resources without authorization or proper
compensation.
8. Thou shalt not appropriate other people’s intellectual output.
9. Thou shalt think about the social consequences of the program you are writing or the system
you are designing.
10. Thou shalt always use a computer in ways that ensure consideration and respect for your
fellow humans.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 37
Ethical Differences Across Cultures
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 38
Ethics and Education
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 39
Deterring Unethical and Illegal Behavior
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 40
Deterrents to Illegal or Unethical Behaviour
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 41
Codes of Ethics of Professional
Organizations
• Many professional organizations have established codes of conduct/ethics.
• Codes of ethics can have a positive effect; unfortunately, many employers do
not encourage joining these professional organizations.
• Responsibility of security professionals is to act ethically and according to the
policies of the employer, the professional organization, and the laws of society.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 42
Professional Organizations of Interest to
Information Security Professionals (1 of 2)
Professional Organization Web Resource Location Description and Link to Code of Ethics
ACM [Link] The ACM is the oldest computing society; its
code of ethics requires members to perform their
duties in a manner befitting an ethical computing
professional.
[Link]/code-of-ethics
ISACA [Link] Promotes a code of ethics for its certification
holders, including CISA and CISM.
[Link]/credentialing/code-of-
professional-ethics
ISSA [Link] Professional association of security
professionals.
[Link]/page/CodeofEthics
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 43
Professional Organizations of Interest to
Information Security Professionals (2 of 2)
Professional Organization Web Resource Location Description and Link to Code of Ethics
(ISC)2 [Link] Promotes a code of ethics based on four canons
for its certification holders, including CISSP and
SSCP.
[Link]/Ethics
SANS GIAC [Link] Promotes a code of ethics based on respect for
the public, the certification, and its certification
holders, including GIAC and GSE.
[Link]/about/ethics
EC-Council [Link] Promotes a code of ethics for its certification
holders, including CCISO and CEH.
[Link]/code-of-ethics/
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 44
Major IT & InfoSec Professional
Organizations (1 of 3)
• Association of Computing Machinery (ACM)
‒ Established in 1947 as “the world’s first educational and scientific computing
society.”
‒ Code of ethics contains references to protecting information confidentiality, causing
no harm, protecting others’ privacy, and respecting others’ intellectual property and
copyrights.
• International Information Systems Security Certification Consortium, Inc. (ISC)2
− Non-profit organization focusing on the development and implementation of
information security certifications and credentials.
− Code is primarily designed for the information security professionals who have
certification from (ISC)2.
− Code of ethics focuses on four mandatory canons.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 45
Major IT & InfoSec Professional
Organizations (2 of 3)
• SANS (originally System Administration, Networking, and Security Institute)
‒ Professional organization with a large membership dedicated to the
protection of information and systems.
‒ SANS offers a set of certifications called Global Information Assurance
Certification (GIAC).
• ISACA (originally Information Systems Audit and Control Association)
− Professional association with focus on auditing, control, and security
− Concentrates on providing IT control practices and standards
− ISACA has a code of ethics for its professionals
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 46
Major IT & InfoSec Professional
Organizations (3 of 3)
• Information Systems Security Association (ISSA)
‒ Non-profit society of information security (IS) professionals.
‒ Primary mission to bring together qualified IS practitioners for information
exchange and educational development.
‒ Promotes code of ethics similar to (ISC)2, ISACA, and ACM.
• EC-Council
− Another security certification organization, with more than 220,000 certified
professionals in more than 145 countries.
− Offers a variety of security technical and managerial certifications, building
on its renowned Certified Ethical Hacker (CEH) and CCISO certifications.
− Promotes a 19-point code of ethics for certification holders.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 47
Key U.S. Federal Agencies (1 of 3)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 49
Key U.S. Federal Agencies (2 of 3)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 50
FBI Cyber’s Most Wanted List
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 51
Key U.S. Federal Agencies (3 of 3)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 52
Knowledge Check Activity 4
Which U.S. Federal agency is most responsible for developing and using
encryption?
a. FBI
b. Secret Service
c. National Institute for Science and Technology
d. National Security Agency
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 53
Knowledge Check Activity 4: Answer
Which U.S. Federal agency is most responsible for developing and using encryption?
a. FBI
b. Secret Service
c. National Institute for Science and Technology
d. National Security Agency
The National Security Agency (NSA) is the nation’s cryptologic organization and is
responsible for signal intelligence and information assurance.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 54
Summary (1 of 3)
• Laws are formally adopted rules for acceptable behavior in modern society. Ethics are
socially acceptable behavior. The key difference between laws and ethics is that laws
carry the authority of a governing body and ethics do not.
• Organizations formalize desired behavior in documents called policies. Policies must
be read and agreed to before they are binding.
• Civil law comprises a wide variety of laws that govern a nation or state. Criminal law
addresses violations that harm society and is enforced by agents of the state or nation.
• Private law focuses on individual relationships, and public law governs regulatory
agencies. Key U.S. laws to protect privacy include the Federal Privacy Act of 1974, the
Electronic Communications Privacy Act of 1986, and the Health Insurance Portability
and Accountability Act of 1996.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 55
Summary (2 of 3)
• The desire to protect national security, trade secrets, and a variety of other state and
private assets has led to the passage of several laws that restrict what information,
information management resources, and security resources may be exported from the
United States.
• Intellectual property is recognized as a protected asset in this country. U.S. copyright
law extends this privilege to published works, including electronic media.
• Studies have determined that people of differing nationalities have varying perspectives
on ethical practices with the use of computer technology.
• Deterrence can prevent an illegal or unethical activity from occurring. Deterrence
requires significant penalties, a high probability of apprehension, and an expectation
that penalties will be enforced.
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 56
Summary (3 of 3)
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 57
Self-Assessment
Michael E. Whitman and Herbert J. Mattord, Principles of Information Security, 7th Edition. © 2022 Cengage. All Rights Reserved. May not be
scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 58