City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.8 Law, Ethics and IT Governance in Information Security

- one subject, every graph, every model, every mark
9 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 8 of 10 · IS6523

Law, Ethics and IT Governance in Information Security

Three obligations with three different consequences

Laws are rules that mandate or prohibit certain societal behaviour. Ethics define socially acceptable behaviour and rest on cultural mores, the fixed moral attitudes or customs of a group. The difference the session draws is not seriousness but enforcement: laws carry the sanctions of a governing authority and ethics do not.

Policy is the third term and behaves like neither, functioning as law inside an organisation while carrying one clause that changes everything, since ignorance of a policy is an acceptable defence.

Privacy as a regime, not as a breach response

Trading online means trading internationally, and the session is candid that political complexity and cultural difference leave few international laws on privacy and information security, and those that do exist are important but limited in enforceability.

The local regime it names runs on six data protection principles covering collection, accuracy and retention, use, security, openness, and access and correction. Only one of the six concerns keeping data safe, which is the correction most student answers in this area need.

The European regulation named alongside has the same shape, designed to harmonise law and reshape how organisations approach data privacy rather than to respond to incidents.

Governance, a framework and a statute

Governance is something executives and the board of a company own together, consisting of the leadership, structures and processes that ensure enterprise technology sustains the organisation's strategies, and it is described as a critical part of corporate governance.

The argument for placing it there is financial: because systems produce, alter, hold and carry critical financial data, officers must build controls that let the information stand up to audit. Two instruments follow and they are different in kind. A control objectives framework is adopted and adapted; a corporate reporting statute is obeyed, with a defined scope and penalties from fines to imprisonment.

In this chapter

What this chapter covers

  • 01

    Law, ethics and cultural mores, and which carries a sanction

  • 02

    Policy as organisational law, and the defence of ignorance

  • 03

    International agreements and the limits of enforceability

  • 04

    Privacy and the aggregation capability behind its urgency

  • 05

    Six data protection principles, only one about safety

  • 06

    Governance as a board responsibility

  • 07

    A control framework against a reporting statute

  • 08

    The ranking of the three characteristics under a reporting obligation

  • 09

    Eight relationships in a professional code

Worked example · free

Answer a note that says no leak means no problem

Q [7 marks]. AskSia-authored practice. A retailer keeps purchase histories indefinitely so its recommendation engine has more to learn from. Customers were told at sign-up that their details would be used to fulfil orders. A customer asks what is held about them and wants two entries corrected. An internal note argues none of this is a security question because nothing has leaked. The marks shown are an AskSia study allocation, not a University marking scheme.
  • 1Concede what the note gets right.
  • 3Name the principles engaged by the retention and by the training use.
  • 3Characterise the customer's request correctly.
The note is right that no breach of the security principle has occurred, and wrong that this settles anything, because it has mistaken one principle for the whole regime. Retaining purchase histories indefinitely runs against the accuracy and retention principle, which limits how long identifying data is kept rather than who may see it. Training a recommendation engine on order data is a use beyond the purpose stated at collection, which is the data use principle. The customer's request is the access and correction principle operating as designed, so it is a duty rather than a complaint, and the openness principle obliges the firm to be able to state its policies and practices on the data it holds in the first place.
Sia tip — Test a data protection question against all six principles, not just security. Ask in order whether collection, retention, purpose, safety, openness or correction is engaged; at least one of the other five usually is while nothing has leaked.
Glossary

Key terms

Cultural Mores
The settled moral attitudes or customs a particular group holds, on which the course says ethics rest.
Policy
A body of expectations describing acceptable and unacceptable employee behaviour, functioning as law within an organisation but carrying no authority sanction and admitting ignorance as a defence.
Privacy
A state of freedom from intrusion that has not been sanctioned. The course attributes its urgency to being able to bring data together from many sources into databases previously impossible.
Data Use Principle
The data protection principle limiting the use of personal data to the purpose for which it was collected.
Accuracy and Retention Principle
The data protection principle requiring personal data to be kept correct and not kept longer than is needed.
Information Technology Governance
The leadership, organisational structures and processes, exercised by executives and the board, that ensure enterprise technology sustains the organisation's strategies and objectives.
Control Framework
A structure for managing and controlling technology activities that an organisation adopts and adapts, as distinct from a statute, which it obeys.
FAQ

Law, Ethics and IT Governance in Information Security FAQ

If a firm has no rule about removable storage, has an employee who copied data done anything wrong?

At the policy layer, very little can be said against the individual, because there is no policy and ignorance of a policy is an acceptable defence, so the finding indicts the organisation. At the legal layer the position is different and does not depend on the firm's rules, since the data use and security principles apply to the organisation as holder of personal data regardless of what it has written down.

An ethical judgement is available but carries no sanction.

Does adopting a recognised control framework make an organisation legally compliant?

No. A framework is adopted and adapted by choice, while a statute has a defined scope and penalties. Adoption may be strong evidence that reasonable steps were taken, which is the argument from due care and from diligence, but compliance is determined against the statute's own requirements. Treating the two as interchangeable is one of the clearer errors available in this part of the course.

Why does the course say confidentiality matters least for the reporting statute?

Because the obligation is about financial reporting rather than about secrecy. The act makes executives responsible for internal control over financial reporting, technology is the foundation of that control, and technology staff answer for keeping the information those systems produce available and intact.

A reporting obligation cares that the numbers are right and can be produced; it is a privacy regime that cares who else saw them.

Is information security a profession in the sense the course uses?

Not by the attributes it lists. Certification and licensing are not compulsory, a degree is not required, an apprenticeship is not required, membership of a professional society is optional, and continuing education is only required of professional members.

The course adds that the field has no binding codes of ethics and that associations can prescribe conduct without always being able to ban violators, so the obligation rests on the individual practitioner.

Study strategy

Exam move

Take the six data protection principles and write beside each a situation in which it is breached while nothing has leaked, which is the single most productive twenty minutes available in this chapter. Then write one sentence separating a framework from a statute and keep it ready, because the distinction is examinable in both directions.

Finish by listing the eight relationships in the code and naming the pair most likely to conflict in practice.

Working through Law, Ethics and IT Governance in Information Security in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Law, Ethics and IT Governance in Information Security question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works