ADMS 2511 Management Information Systems (MIS) Session 3 Ethics, Privacy, Information Security and Controls Mohsen Javdan Fall 2025; Thursdays VH 1152A Agenda Session 3 ➢ Review Chapters 1&2 ➢ Chapter 3: Ethics and Privacy ➢ Break ➢ Chapter 4: Information Security ➢ Kahoot ➢ Practice Case Questions Sep. 18, 2025 MIS 3 Review Chapters 1 & 2 ➢ Information Systems (IS) and Information Technology (IT) ➢ Data, Information, Knowledge ➢ Different types of ISs (ERP, TPS, MIS, etc.) ➢ Business Process Optimization (BPR, BPI, BPM) ➢ Business Pressures, Competitive advantage & Strategic ISs ➢ Porters Competitive Forces & Value Chain Model Sep. 18, 2025 MIS 4 Business Pressures Sep. 18, 2025 MIS 5 Outline ➢ Chapter 3 ● Ethical issues ● Privacy ➢ Chapter 4 ● Information Security ● Unintentional and Deliberate Threats to Information Systems ● Organizations responses to Protect Information Resources ● Information Security Controls ● Personal Information Asset Protection Sep. 18, 2025 MIS 6 Chapter 3. Ethics and Privacy WEE K3 Sep. 18, 2025 MIS 7 Opening Case ➢ Facial Recognition in India Raises Concerns ● Questions: ▪ Discuss the ethics and legality of the Telangana authorities’ capture and use of personal data, including photos and biometric data. o (compare with Police of Toronto) ▪ Discuss the ethics and legality of the Telangana authorities’ use of facial recognition software. ▪ The Telangana police maintain that the department’s use of technology has reduced the crime rate, enabled the police to quickly apprehend suspects, and helped find missing children. Discuss the ethics of the tradeoff between these advantages and the loss of privacy for citizens. Sep. 18, 2025 MIS 8 Introduction ➢ Ethical issues ● Ethics ▪ The principle of right and wrong ▪ People use ethics to make choices that guide their behaviors. ➢ Ethical Frameworks ● Utilitarian approach ● The rights approach ● Fairness approach ● Common good approach ● Deontology approach Images: https://serokell.io/blog/ai-ethics-guide Sep. 18, 2025 MIS 12 Ethical Frameworks ➢ An ethical action in the: ● Utilitarian approach provides the most good or does the least harm ● Rights approach best protects and respects the moral rights of affected people. ● Fairness approach treats all human beings equally. ● Common good approach: Respect and compassion as the basis for ethical actions. ● Deontology approach is based on whether that action itself is wright or wrong. Sep. 18, 2025 MIS 13 Ethics in the Corporate Environment ➢ Code of ethics ● A collection of principles to guide members of the organization for decision making ▪ E.g., ACM (Association for Computing Machinery) ● Different codes of ethics are not always consistent with one another. ▪ E.g., working for two large professional firms with different codes of ethics o One might require to comply with all applicable laws but the other to refuse to obey unjust laws. Accountants and Psychologists codes of ethics Sep. 18, 2025 MIS 16 Fundamental Tenets of Ethics ➢ Responsibility ● Recognizing and acting upon multiple principles and values. ➢ Accountability ● Determining who is responsible for actions that were taken. ➢ Liability ● Gives individuals the right to cover the damages done to them by other individuals, organizations, or systems. Sep. 18, 2025 MIS 17 Poor Ethical Decisions ➢ Poor Ethical decisions can have serious consequences ● US: Enron scandal ▪ Accounting scandal ▪ The passage of the Sarbanes-Oxley Act in 2002 o Aimed at increasing corporate transparency and accountability. ▪ Public companies implement financial controls to ensure: o Accountability: Executives must personally certify financial reports. ● Canada: Nortel and Southam ▪ Bill 198, the Budget measures Act o Imposes similar requirements of mgmt. Sep. 18, 2025 MIS 18 IT and Ethical Problems ➢ Advancements ● Computer processing power ● More storage space at lower prices ● Network & Internet ➢ Numerous ethical problems ● The appropriate collection and use of customer information ● Personal privacy ▪ Google is analyzing search histories and location data o Google can inform retailer whether people who viewed an ad for a lawn mower later visited a Home Depot store. Sep. 18, 2025 MIS 21 Google vs. Ethical Concerns Sep. 18, 2025 MIS 22 Ethics and Information Technology ➢ Many business decisions have an ethical dimension ● Should organizations monitor employees’ Web surfing and email? ● Should organizations sell customer information to other companies? ● Should organizations audit employees’ computers for unauthorized software or illegally downloaded music or video files? Sep. 18, 2025 MIS 23 IT applications and Ethical issues ➢ Privacy issues ● What info of individuals should be allowed to be collected, stored, and disclosed ➢ Accuracy issues ● The authenticity, integrity, and correctness of information ➢ Property issues ● The ownership and value of information ➢ Accessibility issues ● Who should have access to information Sep. 18, 2025 MIS 24 Privacy Sep. 18, 2025 MIS 26 Privacy ➢ Privacy ● The right to be left alone and to be free of unreasonable personal intrusions. ➢ Information Privacy ● The right to determine when, and to what extent, information about you can be gathered or communicated to others. ➢ The right to privacy ● Recognized in all Canadian provinces, the U.S. states, and by both federal governments. Sep. 18, 2025 MIS 27 Digital Dossier ➢ Definition ● An electronic profile of individuals and their habits. ➢ Profiling ● The process of forming a digital dossier ➢ Sources of data ● Surveillance cameras; credit card transactions; telephone calls; banking transactions; queries to search engines; & government records. Sep. 18, 2025 MIS 28 Data Aggregators ➢ Collect public data, then integrate these data to form digital dossiers ➢ Profilers ● US: LexisNexis & Acxiom ● Canada: Statistics Canada; Canada’s national statistics agency ➢ Users of digital dossiers ● Law enforcement agencies ● Companies conducting background check ● Companies interested in knowing their customers better ▪ Customer intimacy process Sep. 18, 2025 MIS 29 Electronic Surveillance ➢ Emergence of new technologies ● Surveillance cameras (airports, subways, banks, stores, etc.) ● Digital sensors (laptop webcams, video game motion sensors, smartphone cameras, utility meters, passports, employee ID cards) ● License plate can be recorded (street, toll bridge, shopping mall parking lot etc.) ● Smartphones ▪ Processing capabilities increased 13,000 since 2000 ▪ GPS sensors: Geotag photos and videos. ▪ Embedding images with location info (longitude & latitude) – Supplying criminals ▪ Facial recognition technology: In-store digital billboards recognize your face Sep. 18, 2025 MIS 31 Electronic Surveillance - Examples ➢ Social Credit Score (SCS) in China ● Every citizen in China would be given a score (available for all to see) ▪ Scores come from monitoring an individual’s social behavior o Spending habits, how regularly pay their bills, etc. ▪ SCS is the basis of a person’s trustworthiness o Publicly ranked ▪ SCS affects people eligibility for a number of services o Jobs, mortgages, the schools for which their children qualify. ● SCS partnered with private companies ▪ China rapid finance (through its WeChat messaging app) ▪ Tencent, Sesame credit (through its AliPay payment service) Sep. 18, 2025 MIS 32 Electronic Surveillance - Examples ➢ Google & Facebook ● Using facial recognition software ● Facebook Photo Album ▪ Online photo editing and sharing services ▪ Photo Tagging (quickly group photos in which the tagged person appears) ● Tagging is important ▪ Once you are tagged in a photo, that photo can be used to search for matches across the entire Internet or in private database. ➢ Drones ● Low-cost drones with high performance cameras can be used for persistent aerial surveillance. Sep. 18, 2025 MIS 33 Electronic Surveillance – By employers ➢ The law supports the right of employers to: ● Read their employees’ email and other electronic documents ● Monitor their employee’s Internet usage ➢ Routinely monitor their employee’s Internet usage ● More than 3/4 of organizations ➢ Use software to block connections to inappropriate websites ▪ URL filtering o 2/3 of organizations ➢ Installing monitoring and filtering software ● Blocking malicious software ● Discouraging employees from wasting time Sep. 18, 2025 MIS 34 Personal Information in Databases ➢ Institutions store personal information ● Credit-reporting agencies, banks & financial institutions, cable TV, telephone, utility companies, employers, mortgage companies, hospitals, schools & universities, government agencies (CRA), etc. ➢ Major concerns about the info. stored by record keepers ● Do you know where the records are? ● Are the records accurate? ● Can you change inaccurate data? ● Under what circumstances will the personal data be released? ● To whom are the data given or sold? ● How secure are the data against access by unauthorized people? Sep. 18, 2025 MIS 35 Privacy Codes and Policies ➢ Guidelines for protecting the privacy of organization’s ● Customers, clients, and employees. ➢ Opt-out model ● Permits the company to collect personal information until the customer specifically requests that the data not be collected. ➢ Opt-in model ● Prohibits an organization from collecting any personal information unless the customer specifically authorizes it. Sep. 18, 2025 MIS 36 Privacy Policy Guideline ➢ Opt-out model is the common approach. ➢ Canada’s privacy commissioner ● Consent should be sought ● Opt-in model ➢ Canada’s anti-spam legislation ● Bill C-28 requires opt-in model for sending emails. ➢ Canada’s privacy legislation ● Personal Information Protection & Electronic Documents Act (PIPEDA) Sep. 18, 2025 MIS 37 Canada’s PIPEDA privacy legislation principles ➢ Accountability ➢ Accuracy ➢ Identifying purposes ➢ Safeguards ➢ Consent ➢ Openness ➢ Limiting collection ➢ Individual access ➢ Limiting use, disclosure, & retention ➢ Challenging compliance Sep. 18, 2025 MIS 38 Canada PIPEDA Sep. 18, 2025 MIS 39 International Aspects of Privacy ➢ Highly complex global legal framework ● Approximately 50 countries have data protection laws ● Many of these laws conflict with those of other countries. ● The absence of consistent or uniform standards for privacy & security ● The EU protection laws and Canadian ones are stricter than the US laws ▪ Could create problems for US-based multinational corporations Sep. 18, 2025 MIS 41 General Data Protection Regulation (GDPR) ➢ The world’s strongest data protection laws ➢ Went into effect in the European Union ➢ Modernizes laws that protect the personal information ➢ Covers both personal data and sensitive personal data ● Personal data: Used to identify a person ▪ Name, address, Internet protocol address, etc. ● Sensitive personal data ▪ Genetic data, racial information, info about religious and political views, sexual orientation, trade union membership, medical records, etc. Sep. 18, 2025 MIS 42 GDPR application ➢ Keep minimal data on each data subject ➢ Secure them properly ➢ Ensure the accuracy ➢ Retain the data for just as long as they are needed Sep. 18, 2025 MIS 43 Questions? Sep. 18, 2025 MIS 44 Break 10 MINUTES Sep. 18, 2025 MIS 45 Information Security CHAPTER 4 Information Security ➢ Security ● Protection against criminal activity, danger, damage, or loss. ➢ Information Security ● All of the processes and policies designed to protect an organization’s information and information system (IS) from: ▪ Unauthorized access, use, disclosure, disruption, modification, or destruction o Threat o Exposure o Vulnerability Sep. 18, 2025 MIS 47 Sep. 18, 2025 MIS 48 Human Mistakes Sep. 18, 2025 MIS 49 Unintentional Threats ➢ Acts performed without malicious intent but with serious threat to information security ● Human errors ▪ A password for the Hawaii emergency agency was hiding in a public photo, written on a Post-it note Sep. 18, 2025 MIS 50 Unintentional Threats ➢ Social engineering ● An attack in which the perpetrator uses social skills to trick or manipulate a legitimate employee into providing confidential company information such as passwords. ▪ Phishing scams ▪ Direct contact ▪ Business email compromise Source: https://vpnoverview.com/ Sep. 18, 2025 MIS 51 Deliberate Threat ➢ Espionage or trespass ● Unauthorized individuals attempt to gain illegal access to organizational information. ➢ Information extortion ● An attacker either threatens to steal or actually steals information from a company. ➢ Sabotage or Vandalism ● Deliberate act of defacing an organization’s website. Sep. 18, 2025 MIS 52 Deliberate Threat (cont.) ➢ Theft or equipment or information ● Laptops, iPads, smartphones, digital cameras, flash drives, etc. ➢ Identity Theft ● Deliberate assumption’s of another person’s identity ▪ To gain access to their financial information ➢ Compromises to intellectual property ● Intellectual property ▪ Trade secret, copyright, patent, etc. Sep. 18, 2025 MIS 53 Software Attacks Sep. 18, 2025 MIS 54 Ransomware ➢ Digital extortion blocks access to a computer system ➢ Encrypt an organization’s data ➢ Until the organization pays a sum of money. ● Mostly in the form of bitcoin ➢ Types of Ransomware: ● Locky, Cryptolocker, WannaCry, Petya, etc. ➢ They decrypt some data for free ● To show victims that they can get the remainder. Sep. 18, 2025 MIS 56 Alien Software ➢ Alien or Pestware ● Owners of computers are unaware of the software. ● Clandestine (secret) software that is installed on your computer ➢ Not malicious as viruses, worms, or Trojan horses. ➢ Uses up valuable system resources ➢ Enables other parties to track your Web surfing habits ➢ Spyware ● Keystroke loggers (keyloggers) or Screen scrapers. Sep. 18, 2025 MIS 57 Supervisory Control and Data Acquisition (SCADA) Attack Sep. 18, 2025 MIS 58 Protect Information Resources - Challenges Sep. 18, 2025 MIS 59 Risk Management ➢ Risk ● The probability that a threat will impact an information resources. ➢ Goal of risk management ● To identify, control, and minimize the impact of threats. ➢ Risk management processes ● Risk Analysis ● Risk Mitigation ● Controls evaluation Sep. 18, 2025 MIS 60 Controls Control Environment Controls General Controls Sep. 18, 2025 Application Control MIS 61 Information Security General Controls Sep. 18, 2025 MIS 62 Controls ➢ Physical Controls ➢ Access Controls ● Authentication ▪ Sth the user is ▪ Sth the user has ▪ Sth the user knows ● Authorization Sep. 18, 2025 MIS 63 Communications Controls (Firewall) Sep. 18, 2025 MIS 65 Communications Controls (Encryption) Sep. 18, 2025 MIS 66 Digital Certificate Sep. 18, 2025 MIS 67 Virtual Private Network (VPN) Sep. 18, 2025 MIS 68 Application Controls ➢ Input Controls ● Accuracy ● Completeness ➢ Process Controls ● Data is processed, stored, as intended. ➢ Output control ● Accurate ● Properly distributed ▪ To authorized individuals Sep. 18, 2025 MIS 69 Questions Sep. 18, 2025 MIS 71 Kahoot QUIZ Sep. 18, 2025 MIS 72 Final Remarks ➢ Do the weekly online quiz (session 3) before the deadline (Oct. 02 11:00 AM) ➢ Do practice questions both case and MCQs ➢ Do Max Lab 1a by Friday, Sep. 26th at 11:00 AM ➢ If you have any questions, do not hesitate to ask (mjavdan@yorku.ca) Sep. 18, 2025 MIS 73 Practice Case Questions 20 MINUTES Sep. 18, 2025 MIS 74 Thank you for your attention! Sep. 18, 2025 MIS 75
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )