Cybersecurity Ethics
This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues.
Course Material
This course helped me understand that cybersecurity is not only about computers, networks, passwords, or protecting information. It is also about people, responsibility, trust, and making ethical decisions. Before taking this course, I already had some strong opinions about right and wrong, especially about privacy. However, the course helped me look at these issues from different perspectives and understand that ethical situations can sometimes be more complicated than they first appear. Three topics that had the biggest impact on me were privacy, professional ethics, and information warfare.
1. Privacy
Privacy was one of the topics that I connected with the most. Even before this course, I believed that every person deserves privacy. I believe that everyone should have a space where they can live without constantly feeling watched or judged. Not everyone is comfortable sharing personal information, and I strongly believe that we should respect that.
During the privacy module, however, I started thinking about privacy in a deeper way. The readings and case study helped me understand that privacy is not only about keeping secrets. It is also about having control over personal information and being able to decide who can access or use it. I learned that information can be misused even when it may seem harmless or available to others.
My position did not completely change because I already believed privacy was important, but it became stronger and more informed. I also realized how important privacy is in cybersecurity because cybersecurity professionals may have access to very sensitive information. Having access to someone’s information does not mean that we have the right to use it however we want.
Takeaway for my future self: Just because I can access someone’s information does not mean I have the right to access, share, or use it. I should always remember that there is a real person behind the data.
2. Professional Ethics
The second topic that changed my thinking was professional ethics. Before this course, I thought being a good cybersecurity professional mainly meant having the technical knowledge to protect systems and solve security problems. I now understand that technical skills are only one part of being a good professional.
The module introduced professional codes such as the ACM and IEEE codes of ethics. These materials made me think about the responsibility that comes with working in technology. A cybersecurity professional may have access to private information, company systems, passwords, networks, and other sensitive resources. Because of this, a person can potentially cause a lot of harm if they do not act responsibly.
I also learned that following the law is not always the same thing as making the best ethical decision. A cybersecurity professional may face situations where there are competing responsibilities or where the correct decision is not immediately obvious. This made me realize that I need to think about the effects of my decisions on other people, not only whether I am technically allowed to do something.
My thinking changed from seeing cybersecurity mostly as a technical career to seeing it as a career that requires honesty, responsibility, trust, and good judgment.
Takeaway for my future self: Being good at cybersecurity is not enough. I want to be a professional who people can trust with their information and systems.
3. Information Warfare
Information warfare was another topic that made me think differently. Before this course, I mostly thought of warfare as something involving physical weapons, soldiers, and military equipment. I did not think as much about information itself being used as a weapon.
The information warfare module helped me understand how social media, information, and communication can be used to influence people’s beliefs and behavior. Information can be manipulated, spread quickly, and used to create fear, confusion, or division. This made me realize that cybersecurity is connected to society in ways that go beyond protecting computers.
My understanding also became more nuanced because information is not always simply true or false. Sometimes the information may be technically true but presented in a way that is designed to influence people. This made me think more carefully about what I see online and how information can affect individuals and communities.
As a future cybersecurity professional, I think this is important because technology can be used both to protect people and to manipulate them. Understanding that difference is part of being responsible in this field.
Takeaway for my future self: I should never underestimate the power of information. Before believing or sharing something, I should think about where it came from, why it was created, and how it could affect other people.
Conclusion
Overall, this course changed the way I think about cybersecurity and ethics. Privacy taught me to respect people’s personal information, professional ethics taught me about the responsibility that comes with working in cybersecurity, and information warfare showed me how technology and information can affect society on a much larger level. I came into this course thinking more about what technology can do. I am leaving it thinking more about what we should do with that technology. As I continue my education and career in cybersecurity, I want to remember that behind every system, account, and piece of data is a person who can be affected by my decisions.