![企業(yè)信息管理課件:Managing Ethical and Legal Issues_第1頁(yè)](http://file4.renrendoc.com/view10/M02/16/33/wKhkGWeWXN-Aa-E2AAFFbR8or9Q602.jpg)
![企業(yè)信息管理課件:Managing Ethical and Legal Issues_第2頁(yè)](http://file4.renrendoc.com/view10/M02/16/33/wKhkGWeWXN-Aa-E2AAFFbR8or9Q6022.jpg)
![企業(yè)信息管理課件:Managing Ethical and Legal Issues_第3頁(yè)](http://file4.renrendoc.com/view10/M02/16/33/wKhkGWeWXN-Aa-E2AAFFbR8or9Q6023.jpg)
![企業(yè)信息管理課件:Managing Ethical and Legal Issues_第4頁(yè)](http://file4.renrendoc.com/view10/M02/16/33/wKhkGWeWXN-Aa-E2AAFFbR8or9Q6024.jpg)
![企業(yè)信息管理課件:Managing Ethical and Legal Issues_第5頁(yè)](http://file4.renrendoc.com/view10/M02/16/33/wKhkGWeWXN-Aa-E2AAFFbR8or9Q6025.jpg)
版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
ManagingEthicalandLegalIssuesLearningoutcomesAfterthislecture,youwillbeableto:Understandtheimplicationsofprivacyanddataprotectionlegislationformanagers;Assessapproachestoprovidingandmonitoringemployeeaccesstoinformation;Definetherisksofunauthorizeddataaccessandsolutionstocounterthem.ManagementissuesTypicalquestionsfacingmanagersrelatedtothistopic:Whatarethelegalconstraintsonmanagingcustomerandemployeedata?Whataretherisksofunauthorizedaccesstodataandhowcanweminimizethese?Whatisthebalancebetweenbusinessimperativeandmoralstanceformonitoringandcontrollingemployeedataaccess?LegalandethicalchallengesofIMMarketingwithdirectmailande-mail(SPAM)ManagingcustomerandemployeeprivacyIdentitytheftHackersandsabotageDisabilityanddiscriminationactCopyrightEthicsEthicalstandardsarepersonalorbusinesspracticesorbehaviourwhicharegenerallyconsideredacceptablebysociety.Acceptableethicscanbedescribedasmoralorjustandunethicalpracticesimmoralorunjust.Sometimes(often)businesspracticesarewithinthelaw,butcannotbeconsideredethical.LawsevolvetomandateethicalbehaviourUnethicalbusinesspracticesthatarenowcoveredbylawinclude:Sendingunsolicitede-mailcommunicationsPassingsensitivepersonalinformationontoathirdpartyUnauthorisedaccessedtocompetitordataCopyrightinfringementsSarbanesOxley(promptedbyEnron)In2002,theUSgovernmentpassedtheSarbanesOxleyAct(SarboxorSOXforshort),whichredefineslegallyacceptableaccountingpractices.Essentially,thelawrequiresseniormanagementtoberesponsiblefortheaccuracyoftheirfinancialreporting,inotherwordsinformationquality.Thekeyclauseis:Section302:CorporateResponsibilityForFinancialReports.‘TheCEOandCFOofeachissuershallprepareastatementtoaccompanytheauditreporttocertifythe‘a(chǎn)ppropriatenessofthefinancialstatementsanddisclosurescontainedintheperiodicreport,andthatthosefinancialstatementsanddisclosuresfairlypresent,inallmaterialrespects,theoperationsandfinancialconditionoftheissuer.’‘Sarbox’continuedFurthermore,Section404:ManagementAssessmentOfInternalControlsrequires: an"internalcontrolreport",whichshall: (1)statetheresponsibilityofmanagementforestablishingandmaintaininganadequateinternalcontrolstructureandproceduresforfinancialreporting;and (2)containanassessment,asoftheendoftheissuer'sfiscalyear,oftheeffectivenessoftheinternalcontrolstructureandproceduresoftheissuerforfinancialreporting.TheDigitalDivideTheUnitedNations,ina1999reportonhumandevelopmentnotedthatparallelworldsaredevelopingwhere‘thosewithincome,educationand–literally–connectionshavecheapandinstantaneousaccesstoinformation.Therestareleftwithuncertain,slowandcostlyaccess…theadvantageofbeingconnectedwilloverpowerthemarginalandimpoverished,cuttingofftheirvoicesandconcernsfromtheglobalconversation’.ApproachestomanagingtheinformationsocietyBoozAllenHamilton(2002)reviewsapproachesusedbygovernmentstoencourageuseoftheInternet.Theyidentifyfivebroadthemesinpolicy:1.Increasingthepenetrationof‘a(chǎn)ccessdevices’.ApproachesincludeseitherhomeaccessthroughSweden’sPCTaxReform,orinpublicplaces,asinFrance’sprogrammetodevelop7000accesspointsby2003.Francealsoofferataxincentivescheme,wherefirmscanmaketaxfreegiftsofPCstostaffforpersonaluse.2.Increasingskillsandconfidenceoftargetgroups.Thesemaytargetpotentiallyexcludedgroups,aswithFrance’ssignificant150million€campaigntotraintheunemployed.Japan’sITTrainingprogrammesuseexistingmentors.3.Establishing‘DrivingLicences’or‘Passport’qualifications.France,ItalyandtheUKhaveschemeswhichgrantsimpleITqualifications,particularlyatlowskilledgroupssuchasthelong-termunemployed.4.Buildingtrust,orallayingfears.AnexampleofthisintheUSisthe1998ChildOnlineProtectionActwhichusedschemestoprovide‘kitemark’-typeverification,orcertificationofsafeservices.5.Directmarketingcampaigns.Accordingtothereport,onlytheUK,withitsUKOnlinecampaign,ismarketingdirectlytocitizensonalargescale.EstherDysononInternetgovernanceInternetgovernanceisthecontrolputinplacetomanagethegrowthoftheInternetanditsusage.Governanceistraditionallyundertakenbygovernment,buttheglobalnatureoftheInternetmakesitlesspracticalforagovernmenttocontrolcyberspace.
Shesays:‘Now,withtheadventoftheNet,weareprivatisinggovernmentinanewway–notonlyinthetraditionalsenseofsellingthingsofftotheprivatesector,butbyallowingorganizationsindependentoftraditionalgovernmentstotakeoncertain“government”regulatoryroles.ThesenewinternationalregulatoryagencieswillperformformergovernmentfunctionsincounterpointtoincreasinglygloballargecompaniesandalsotoindividualsandsmallerprivateorganizationswhocanoperategloballyovertheNet.’InternetgovernanceissuesCanInternetcontent&activitybecontrolled?Towhatextentshouldthisbeenforced?WhatistherelationshipbetweentheInternetandfreedomofspeech?Whatroleshouldgovernmenttake?Whatroleshouldindustry&businesstake?InternetjurisdictionDyson(1998)describesdifferentlayersofjurisdiction.Theseare:1. Physicalspacecomprisingeachindividualcountrieswheretheirownlawssuchasthosegoverningtaxation,privacyandtradingandadvertisingstandardshold.2. ISPs–theconnectionbetweenthephysicalworldandvirtualworld.Jurisdiction
Thescopeorextentofcontrolofalawgeographically–whoitappliesto.Supra-governmentorganizationsForexample,TheInternetWatchFoundation(.uk)worksinpartnershipwithISPs,Telcos,MobileOperators,SoftwareProviders,PoliceandGovernment,tominimisetheavailabilityofillegalInternetcontentsuchaschildabuseorracistimagesAtthesametime,othernon-profitorganizationssuchasCyberRights()campaignforfreespeech(althoughtheydonotcondoneallmaterialon-line)Therearealsosupra-governmentorganistionswhocontroldifferentaspectsofthetechnologydescribedinChapter2suchasICANNE-governmentE-governmentreferstotheapplicationofe-commercetechnologiestogovernmentandpublicservices.E-governmentcoverselectroniccommunicationswith:Citizens–Findinginformation,payingtaxandbillsSuppliers–E-procurementInternalcommunications–theuseofintranetsforinformationcollectionanddisseminationande-mailandworkflowsystemsforimprovingefficiencycanbedeployedingovernmentdepartments.E-governmentactivities(Aus)Access,participationandskills–Encouragingallsectorsofthecommunitytoactivelyparticipateintheinformationeconomy.Adoptionofe-business–TheGovernmentisworkingtoprovidemoreefficientcommunicationbetweenbusinessestohelpimprovetheproductivityoftheAustralianeconomy.Apriorityfocusfor2002/2003istopromotetheuptakeofelectronicprocurementandbroaderelectronicbusinessprocesses,especiallybysmallandmediumenterprises.Confidence,trustandsecurity–TheGovernmentisworkingtobuildpublictrustandconfidenceingoingonline,andaddressingbarrierstoconsumerconfidenceinecommerceandotherareasofonlinecontentandactivity.e-Governmentstrategiesandimplementation–Theuseofnewtechnologiesforgovernmentinformationprovision,servicedeliveryandadministrationhasthepotentialtotransformgovernment.ThistransformationwillimprovethelivesofAustralians.NOIEprovidesaframeworkandcoordinateswholeofgovernmentapproachestosupportCommonwealthagencyeffortsinthisarea.EnvironmentforInformationeconomyfirms–Provideresearchontheenvironmentalvariablesthatdriveinnovationandgrowthintheinformationeconomyandunderpinitsfuturedevelopment.InternationalDimensions–NOIE,incooperationwithotherGovernmentbodies,representsAustraliainworldforumswheredecisionsaremadethatmayaffectnationalinterestsintheinformationeconomy.UKOnlineActionPlanTheGovernment'smaintargetis:‘Thatby2005,100%ofdealingswithGovernmentshouldbecapableofbeingdeliveredelectronically,wherethereisademand.’Otheraimsinthe‘electronicservicedelivery’programmeare:RefineanalysisofcustomergroupingsandcarryoutcustomerneedsanalysesandtheOfficeofthee-Envoywillworkwithdepartmentstointroducee-businessstrategiesforkeycustomersegmentsEnsurethereisastrategy,withameasurablebaseline,tomaximisetake-upofe-servicesRe-engineerdepartmentalbusinessprocessestofullyexploitnewtechnologiesEnsurethatkeytransactionalservicesaree-enabledviatheGovernmentGatewayDriveforwardcitizenparticipationindemocracyFurtherdevelopacross-GovernmentknowledgemanagementsystemContinuetodriveforwarde-procurementande-tenderingPrivacydefinedInthecontextofinformation,privacyreferstoanindividual’srightsasacustomer,employeeorcitizenaboutwhatpersonaldataisheldaboutthembythirdpartiessuchascompanies,employersandgovernmentagenciesandhowitisused.Personaldatareferstocontactdetailssuchasname,address,phonenumberande-mail.Foracustomeritalsoincludesdetailssuchasproductspurchased,credithistory,whenawebsitehasbeenvisitedorwhiche-mailshavebeenviewed.Foranemployeeitcanalsoincludedetailssuchassalary,sicknessandholidayrecords.PrivacyissuesMason(1986)hasusefullydividedissuesrelatedtoprivacyinto4areas:Privacy–whatinformationisheldabouttheindividual?Arepersonaldetailsheldwhicharenotarguablyrelevanttothebusiness?Accuracy–isitcorrect?Incorrectinformationmaydisadvantageanindividual.Property–whoownsitandhowcanownershipbetransferred?Accessibility–whoisallowedtoaccessthisinformation,andunderwhichconditions?Thisisthesecurityconcern.MoreprivacyissuesFletcher(2001)providesanalternativeperspective,raisingtheseissuesofconcernforboththeindividualandthemarketer:Transparency–whoiscollectingwhatinformation?Security–howisinformationprotectedoncecollectedbyacompany?Liability–whoisresponsibleifdataisabused?DirectmailexpenditureintheUKFigure12.1DirectmailexpenditureintheUKSource:RoyalMail(publishedbyDirectInformationService)Dataprotectiondefined Dataprotectionlegislation Lawintendedtoprotecttheprivacyofconsumers’datathroughdefininghoworganizationscangather,store,processanddisclosepersonalinformation
DataProtectionlegislationistheretoprotecttheindividual;toprotecttheirprivacyandtopreventmisuseoftheirpersonaldata.IndeedthefirstarticleoftheEuropeanUniondirective95/46/EConwhichlegislationinindividualEuropeancountriesisbased,specificallyreferstopersonaldata.Itsays:'...Memberstatesshallprotectthefundamentalrightsandfreedomsofnaturalpersons[i.e.anamedindividualathomeoratwork],andinparticulartheirrighttoprivacywithrespecttotheprocessingofpersonaldata.'DPPrinciples1.Fairlyandlawfullyprocessed.Thisrequiresappointmentofadatacontrollerwhoisapersonwithdefinedresponsibilityfordataprotectionwithinacompany.Cleardetailsincommunicationssuchasonawebsiteordirectmailofhowa‘datasubject’cancontactthedatacontrollerorarepresentative.Beforedataprocessing‘thedatasubjecthasgivenhisconsent’ortheprocessingmustbenecessaryeither
fora‘contracttowhichthedatasubjectisaparty’(forexampleaspartofasaleofaproduct)orbecauseitisrequiredbyotherlaws.Sensitivepersonaldatarequiresparticularcare,thisincludestheracialorethnicoriginofthedatasubject;politicalopinions;religiousbeliefsorotherbeliefsofasimilarnature;membershipofatradeunionphysicalormentalhealthorconditionsexuallife.DPPrinciples2.Processedforlimitedpurposes
Thisimpliesthattheorganizationmustmakeitclearwhyandhowthedatawillbeprocessedatthepointofcollection.Forexample,anorganizationhastoexplainhowyourdatawillbeusedifyouprovideyourdetailsonawebsitewhenenteringaprizedraw.Youwouldalsohavetoagree(giveconsent)forfurthercommunicationsfromthecompany.Onlyprocessedasfarasnecessary.InformationflowsthatneedtobeunderstoodforcompliancewithdataprotectionlegislationFigure12.2InformationflowsthatneedtobeunderstoodforcompliancewithdataprotectionlegislationSource:BIMDPPrinciples3.Adequate,relevantandnotexcessive
Thisspecifiesthattheminimumnecessaryamountofdataisrequestedforprocessing.Forexample,itwouldnotbeapplicableaprizedrawforthecompanytoaskaboutyourcredithistory.Thereisdifficultyinreconcilingthisprovisionbetweentheneedsoftheindividualandtheneedsofthecompany.Themoredetailsthatanorganizationhasaboutacustomer,thenthebettertheycanunderstandthatcustomerandsodevelopproductsandmarketingcommunicationsspecifictothatcustomerwhichtheyaremorelikelytorespondto.DPPrinciples4.AccuracyItisclearlyalsointheinterestofanorganizationinanongoingrelationshipwithapartnerthatthedataiskeptaccurateanduptodate.TheguidelinesontheActsuggeststhatadditionalstepsshouldbetakentocheckdataisaccurate,incasetheyareinerror,forexampleduetomis-keyingbythedatasubject,organizationorsomeotherreason.Inaccuratedataisdefinedintheguidelinesas:‘incorrectormisleadingastoanymatteroffact.’Stepsmustbeinplacetokeepdataup-to-date.DPPrinciples5.Notkeptlongerthannecessary
Theguidelinesstate:‘TocomplywiththisPrinciple,datacontrollerswillneedtoreviewtheirpersonaldataregularlyandtodeletetheinformationwhichisnolongerrequiredfortheirpurposes.’DPPrinciples6.Processedinaccordancewiththedatasubject'srights
Oneaspectofthedatasubject’srightsistheoptiontorequestacopyoftheirpersonaldatafromanorganization,thisisknownasa‘subjectaccessrequest.’Forpaymentofasmallfeesuchas£10or£30,anindividualcanrequestinformationwhichmustbesuppliedbytheorganizationwithin40days.Thisincludesallinformationonpaperfilesandoncomputer.Ifyourequestedthisinformationfromyourbanktheremaybeseveralboxesofalltransactions!Principle6continuedOtheraspectsofadatasubject’srightswhichthelawupholdsaredesignedtopreventorcontrolprocessingwhich:causesdamageordistress(forexamplerepeatedlysendingmailshotstosomeonewhohasdied);isusedfordirectmarketing(forexample,intheUKconsumerscansubscribetothemail,e-mailortelephonepreferenceserviceortelephonepreferenceservicestoavoidunsolicitedmailings,
e-mailsorphonecalls);isusedforautomaticdecisiontaking–automatedcreditchecks,forexamplemayresultinunjustdecisionsontakingaloan–thesecanbeinvestigatedifyoufeelthedecisionisunfair.DPPrinciples7.SecureInfull:‘Appropriatetechnicalandorganizationalmeasuresshallbetakenagainstunauthorisedorunlawfulprocessingofpersonaldataandagainstaccidentallossordestructionof,ordamageto,personaldata.’Appropriatesecurityismandatory.DPPrinciples8.Nottransferredtocountrieswithoutadequateprotection
Infull:‘PersonaldatashallnotbetransferredtoacountryorterritoryoutsidetheEuropeanEconomicArea,unlessthatcountryorterritoryensuresanadequatelevelofprotectionoftherightsandfreedomsofdatasubjectsinrelationtotheprocessingofpersonaldata.’TransferofdatabeyondEuropeislikelyformulti-nationalcompanies.Thisprinciplepreventsexportofdatatocountriesthatdonothavesounddataprocessinglaws.Ifthetransferisrequiredinconcludingasaleorcontractorifthedatasubjectagreestoit,thentransferislegal.ProblemswithDPActinterpretation1InDecember2003anelderlycoupleintheUKdiedthroughhypothermiaaftertheirutilitycompanyhadcutofftheirgassupply.Initiallythepresssupportedthecompanysuggestingthattheutilitysupplierhadmadeeveryefforttoassistthecouple,butdataprotectionlawspreventedthempassingsensitivepersonaldataontosocialwelfareandcharityorganizations.ProblemswithDPActinterpretation2Guardian(2004)quotedthecommissionerassayingthatorganizationsusedtheactasa‘smokescreenfortheirownshortcomings’.Hesuggestedthatcommonsenseshouldbeapplied.Commentingontheutilitiescasehesaid:‘Whereagascompanyisdisconnectingpeopletheyknowtobevulnerable,Idon’thaveaproblemwithtellingsocialservices.Iwouldfinditwhollyunacceptableiftheytoldabankorcreditcardcompany.’
ProblemswithDPActinterpretation3Inafurthercaseinformationaboutsomeonewithsexallegationsagainstthemwasnotpassedonfromonepoliceauthoritytoanotherwhentheywerecheckedforajobasacaretakerandsubsequentlymurderedstudentsbecauseoffearsofpassingonthecaretakerspersonaldata.Commentingonthiscase,thecommissionersaidhehadbeen‘justastonished’bythepoliceforce’sclaimthattheactrequiredthemtodeleteinformationaboutallegationsaboutindividualsthatdidnotleadtoaprosecution.Infactthelawenablesholdingofdataforalongperiodforlegitimatepurposes.PrivacyandElectronicCommunicationsRegulationsAct.Requiresconsenttoreceivee-mailcommunications(Opt-in)Requiresunsubscribeoption(Opt-out)Currentlyappliestoindividualsubscribersi.e.residentsandsmallnon-incorporatedcompaniesAlsoopt-inisunnecessaryforexistingcustomersPrivacystatementmustclearlyexplainhowcookiesareusedViralmarketingmustinvolveasinglefollow-upmessageandincentivesshouldnotbeusedtoprovideotherpeople’saddresses,e.g.winaphoneifyouprovide10otherpeople’se-mailaddressesOnlineforms(a)Opt-out(b)Opt-in(c)Implicitopt-inFigure12.3Onlineforms(a)Opt-out(b)Opt-in(c)Implicitopt-inSource:BIMCookies1Cookiesarestoredasindividualtextfilesinadirectoryonapersonalcomputer.Thereisusuallyonefileperwebsite.Forexample:dave_chaffey@british-airways.txt.Thisfilecontainsencodedinformationasfollows:FLT_VIS|K:bapzRnGdxBYUU|D:Jul-25-1999|/042525990429357426117074793629284034*Cookies2Therearetwoformsofcookies;sessioncookiesandpersistentcookies.Sessioncookiesareusedtomanageasinglevisitorsession,forexampleitmanagestheprocessofaddingitemstoashoppingbasketandthencheckingoutasthewebsitevisitormovesfrompagetopage,theyarestillrecognized.Persistentcookiesremainonthecomputerafteravisitorsessionhasended.Theirmainpurposeistheidentificationofreturningvisitors.Withouttheuseofpersistentcookiesitisnotpossibletouniquelyidentifyanindividualreturningtoawebsitewithoutrequestingtheyidentifythemselvesthroughausername.CookieapplicationsCookiesareusedtoidentifyusersandretrievetheirpreferencesfromadatabase.Forexample,IsubscribetotheE-consultancyservice()forthelatestinformationaboute-business,eachtimeIreturnIdonothavetheannoyanceofhavingtologinbecauseitremembersmypreviousvisit.Manysitesfeaturea‘RememberMe’option.RetailerssuchasAmazoncanalsorecognisereturningvisitorsandcanrecommendrelatedbookspurchasedbyotherreaders.Advertisingnetworksusecookiestotrackthenumberoftimesaparticularcomputerhasbeenshownaparticularbanneradvertisement,theycanalsotrackadvertsservedonsitesacrossanadnetworkandtherewasanindividualrightsoutcryinthelate1990ssinceDoubleclickwasusingthistoprofilecustomers.Doubleclicknolongeroperatesanad-network.SoftwaresuchasWebtrends()whichanalysesstatisticsonvisitorstowebsitesreliesonpersistentcookiestofindtheproportionofrepeatvisitorstoawebsite.Cookies4TheNewPECRlawlimitstheuseofcookie.Itstates:‘a(chǎn)personshallnotuseanelectroniccommunicationsnetworktostoreinformation,ortogainaccesstoinformationstored,intheterminalequipmentofasubscriberoruserunlessthefollowingrequirementsaremet’.Therequirementsare:‘(a)theuserisprovidedwithclearandcomprehensiveinformationaboutthepurposesofthestorageof,oraccessto,thatinformation;and(b)isgiventheopportunitytorefusethestorageoforaccesstothatinformation.’Legal–Sparrow’seightareasMarketingyoure-commercebusiness
(Domainsquattingandcompetitormetatags)
Forminganelectroniccontract
Makingandacceptingpayment
AuthenticatingcontractsconcludedovertheInternetE-mailrisks
ProtectingIntellectualProperty
AdvertisingontheInternet
Dataprotection
FreedomofInformationActTheUKFOIAdoesnotaddresspersonaldataandprivacy,ratheritistoencourageopennessamongstpublicauthorities.Itisintendedtogivecitizensaccesstoinformationheldbypublicauthorities,enablingthemtoparticipate‘inthediscussionofpolicyissuesandsoimprovethequalityofgovernmentdecisionmaking’and‘holdinggovernmentandotherbodiestoaccount’.FOIABylawpublicorganizationsmustproduceaPublicationSchemewhichconsistsoftheclassesofinformationthataremadeavailable.OneimplicationoftheFOIAmaybethatorganizationssellingservicestogovernmentsmaybeabletoaccesswhatwouldformerlybethoughtofaconfidentialdetailsaboutcompetitivebids.Thismaycontaincommerciallysensitiveinformationwhichwillaffecttheoutcomesoffuturebids.However,theActdoesexempttradesecrets.Infact,businessesneedtoconsideralltypesofinformationgiventopublicbodiessinceitmaybedisclosedatalaterdate,althoughthereareexemptions.
EmployeecommunicationsmonitoringEmployeecommunicationsmonitoringorsurveillanceisusedbyorganizationstoreduceproductivitylossesthroughtimewasting.Ifanemployeeearning£25,000peryear,spends30minuteseachdayofa5dayweekansweringpersonale-mailsorvisitingnonwork-relatedwebsites,thiswillcostthecompanyover£1500peryear.Foracompanywith100employees,wheretheaverageemployeeworks46weeksperyear,thisamountstoover£150,000peryearorseveralnewemployees!EmployeemonitoringcaseAtypicalexampleofallegedtimewastingwherethecompanydismissedtheemployeeconcernedinvolvedLoisFranxhi,a28-year-oldITmanagerwhowassackedinJuly1998formakingnearly150searchesoverfourdaysinofficehoursforaholiday.Sheclaimedunfairdismissal–shewaspregnantatthetimeofthedismissal.Aswithmanyunfairdismissals,thecasewasnotclearcut,withMrsFranxhiclaimingthecompanysackedherbecauseofsexdiscrimination.ThetribunaldismissedtheseclaimsfindingthattheemployeehadliedabouttheuseoftheInternet,sayingshehadonlyuseditforonelunchtimewhen,infactrecordsshowedshehaduseditoverfourdays.ApproachestocontrollingusageAcceptableusepolicy
StatementofemployeeactivitiesinvolvinguseofnetworkedcomputersthatarenotconsideredacceptablebymanagementScanningsoftware–scansforphrasesorimagesFilteringsoftware–blockswebsitesImpactassessmentofmonitoringrequiredbylawImpactassessmentinvolves…?‘identifyingclearlythepurpose(s)behindthemonitoringarrangementandthebenefitsitislikelytodeliver?identifyinganylikelyadverseimpactofthemonitoringarrangement?consideringalternativestomonitoringordifferentwaysinwhichitmightbecarriedout?takingintoaccounttheobligationsthatarisefrommonitoring?judgingwhethermonitoringisjustified.’Examplerulestriggeredby
e-mailinNetIQMailMarshallFigure12.4Examplerulestriggeredbye-mailinNetIQMailMarshallSource:NetIQ()IdentitytheftIdentitytheftisanincreasingproblemintheinformationsociety.AccordingtoGuardian(2003a),quotingtheCreditIndustryFraudAvoidanceSystem(Cifas),theUK'sfraudpreventionservice,itisthefastest-growingwhite-collarcrime,generatingacriminalcashflowof£10maday.In1999,therewere20,264reportedcasesofidentitytheftintheUK;butby2002,thatfigurehadreached74,766,andin2003,thefigurewas101,000.IdentitytheftdefinedCIFASdefineidentitytheftasfollows:‘IdentityTheftisthemisappropriationoftheidentityofanotherperson,withouttheirknowledgeorconsent.Broadlyspeaking,identitytheftisanothernameforimpersonationfraud.Thenameandotherpersonaldetailsofanotherindividualareusedtoobtaingoodsandservicesinthatperson’sname.Thekindofinformationusedmayincludedateofbirth,currentaddressorpreviousaddresses–thekindofdetailusedtohelpestablishidentityinanapplicationforallkindsofservices,rangingfromcreditproductstobankaccounts,frominsurancetoutilities.’Identitytheft–howtodoit…Moresophisticatedformsofidentitytheftinvolvesettingupfalsebankorcreditcardsaccountsorevenpassportsusingthestolenidentity–theseoftenuseddiscardedbillsandreceiptswhichmaybethrownoutwiththehouseholdrubbish.CIFASreportedinananalysisof400domesticbins,that72%containedafullnameandaddress,40%containedacreditcardnumberandexpirydatelinkedtoanindividual,and20%heldabankaccountnumberandsortcodealongsideaname.Experianreportedin2002that53outof71localauthoritiesreportedbinraidingwastakingplaceintheirareas,andgettingnoticeablyworse.ApproachestocounterIDtheftIdentitycardsBiometricsRFIDtaggingofobjectsorpeopleRFIDtaggingGuardian(2003b)reportsthatcreditcardcompanyMasterCardisalreadydevelopingsimilartechnology.AMastercardspokesmanwasquotedassaying‘Itcouldbeembeddedinanything-maybeevenundertheskin.’Thearticleasksabouttheriskofsurgicalmuggersattemptingtogougeachipoutofyourarm?MatthewCossolottoofADS,whohashadhimselfchippeds
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025年堿錳電池合作協(xié)議書
- 小學(xué)一年級(jí)2025年秋季學(xué)期語(yǔ)文教學(xué)計(jì)劃
- 2025年企業(yè)公轉(zhuǎn)私借款合同(2篇)
- 2025年九年級(jí)第二學(xué)期思想品德教學(xué)工作總結(jié)(三篇)
- 2025年個(gè)人房屋買賣協(xié)議例文(五篇)
- 2025年買賣合同要式合同(2篇)
- 2025年代理委托貸款協(xié)議(2篇)
- 2025年九年級(jí)初三班主任的工作總結(jié)模版(二篇)
- 2025年二手房買賣購(gòu)房合同樣本(三篇)
- 2025年個(gè)人私人借款合同標(biāo)準(zhǔn)版本(2篇)
- 外科手術(shù)及護(hù)理常規(guī)
- 學(xué)校開學(xué)教師安全培訓(xùn)
- 出口潛力分析報(bào)告
- 大美陜西歡迎你-最全面的陜西省簡(jiǎn)介課件
- 三位數(shù)減三位數(shù)的減法計(jì)算題 200道
- 米粉項(xiàng)目可行性研究報(bào)告
- 蛇年元宵節(jié)燈謎大全(附答案)
- 2023年上海中僑職業(yè)技術(shù)大學(xué)單招考試職業(yè)技能考試模擬試題及答案解析
- 中國(guó)教育公益領(lǐng)域發(fā)展報(bào)告
- 第2章第1節(jié)有機(jī)化學(xué)反應(yīng)類型課件高二下學(xué)期化學(xué)魯科版選擇性必修3
- 生物質(zhì)能利用原理與技術(shù) - 第二章生物質(zhì)能資源與植物
評(píng)論
0/150
提交評(píng)論