Other

Should IT Have Its Own Hippocratic Oath?

This story appears in the November 2006 issue of BizTech Magazine.

 


Photo: Welton Doby III

It’s becoming all too commonplace. A disgruntled systems staffer tampers with a server to reroute and reject the e-mail of the boss who fired him. An information technology manager plants a malicious code “time bomb” on his debt collection company’s network, triggered to corrupt thousands of company records. A contractor hacks into restricted parts of the network while performing a routine infrastructure upgrade.

Think these are provocative fictional accounts? Then Google the names “Roman Meydbray,” “William Carl Shea” and “Joseph Thomas Colon” to find a long list of misdeeds these IT workers committed against their former employers. Colon, for example, was a contractor working for the FBI when he decided to penetrate classified Witness Protection Program and counterespionage files. He used common decryption tools found on the Internet.

Technology is evolving faster than our capacity to rein it in, creating and raising issues that are not easy to address: data access, access tracking and monitoring, systems auditing and benign hacking. As automation catches up to corporate systems and processes and as data readiness needs force businesses to capture more information to better compete, how can businesses ensure that the masters of the electronic domains don’t use their undisputed knowledge and power to wreak havoc?

Medicine has the Hippocratic Oath. The heavily regulated medical profession licenses its practitioners and tracks and restricts the prescription of drugs. But what about IT? Other than a few providers of professional certifications, there’s no professional standards or regulatory body that governs IT or determines what qualifies as ethical behavior. There’s also no governing body that performs or insists on audits of systems logs or demands systematic background checks for IT staffers with security roles or that teaches ethics for systems use. So, would a code of ethics help? For advocates, IT ethics are considered more carrot than stick, but at least it’s a starting point. For detractors, the impact would be minimal.

Still, 43 percent of BizTech readers say IT staffers should be required to certify the security of the systems they supervise and 10 percent report that they’re required to do so by their employers. Although readers apparently like the idea of IT staffers certifying that their systems are secure, only 39 percent think this step will improve security. And another 36 percent of readers are on the fence.

Currently — just like most security breaches — monitoring IT’s access to systems is an inside job. What happens if an IT worker violates his or her employer’s trust? How would they know the transgression even happened? Without some type of auditing or monitoring of systems logs, it may be impossible to discover a security breach. Luckily, the disgruntled workers typically make their menaces known. Shea’s code bomb, for instance, went off not long after his termination. Just like the Sarbanes-Oxley Act tackled the lack of quality assurance for financial data gathered by publicly traded businesses, a similar set of controls for systems security for IT organizations seems likely, especially if these ethical failures continue to surface — and they will.

Lee Copeland
Editor in Chief

Sign up for our e-newsletter

Security

Apple’s iOS 7 Makes Small bu... |
The overhaul and redesign of Apple’s mobile operating system are worth cheering about,...
Why Law Firms Should Live an... |
Firms shouldn’t allow unfounded security concerns to deter them from all the cloud has to...
How 3 Companies Disaster-Pro... |
Despite the havoc following Sandy, these businesses continued services with hardly a...

Storage

3 Questions to Help SMBs Pla... |
Before planning a backup strategy, here are three questions that can help set the...
How 3 Companies Disaster-Pro... |
Despite the havoc following Sandy, these businesses continued services with hardly a...
EMC World 2013: Software-Def... |
Storage virtualization is a key element of providing on-demand, flexible cloud services.

Infrastructure Optimization

Has Open-Source Technology G... |
The days of “open-source” being a dirty word could soon be a distant memory.
West Coast Customs Outfits B... |
The Technoliner gives businesses a hands-on experience with the latest productivity tools...
Spring Cleaning: Refresh Tip... |
Three financial businesses offer advice on optimizing computing operations.

Networking

Cisco Live 2013: Collaborati... |
The way work gets done is set to evolve once machines and sensors jump into the mix.
At the Core of a Thriving Bu... |
Companies find the ability to easily connect with customers and employees essential to...
5 Ways to Fix Common Wi-Fi E... |
Get expert pointers on how optimize your 802.11 network.

Mobile & Wireless

The Mobile Apps Most Commonl... |
Fewer businesses than you might think actively blacklist or whitelist iOS or Android...
Using iPads at Check-In Prov... |
An ambitious mobile strategy built around tablets is helping Hyatt Hotels reach new...
Businesses Go Mobile on Mult... |
A real estate agency and logistics provider tap devices that make their workers more...

Hardware & Software

The Do’s and Don’ts of Email... |
A perfectly crafted email signature can make a great digital impression.
Shopping 2.0: N.Y. Retailer... |
Kate Spade and eBay have teamed up to provide a unique shopping experience that brings...
Apple’s iOS 7 Makes Small bu... |
The overhaul and redesign of Apple’s mobile operating system are worth cheering about,...