Cybersecurity Ethics
This course examines ethical issues relevant to ethics for cybersecurity professionals, including privacy, professional code of conduct, practical conflicts between engineering ethics and business practices, individual and corporate social responsibility, ethical hacking, information warfare, and cyberwarfare. Students will gain a broad understanding of central issues in cyberethics and the ways that fundamental ethical theories relate to these core issues.
Reflective Writing Assignment
Throughout this semester, there have been several topics discussed that pertain to cybersecurity and the many ethical and often “gray” areas that involve cyber warfare. Of them, three topics come to mind that were the highlight of this academic journey. The first of which came early within the course, specifically Module 2, in which I approached the need for the United States to adopt similar legislation and protections as the European Union’s (EU) General Data Protection Regulation has done. For this specific analysis, I used the Kantian Deontology perspective, and argued that this should happen to respect the privacy of citizens, and that businesses have a moral obligation to do so rather than generate profits by selling our private data.
Since this topic, I have done additional research into exactly where our data is used against us. I must admit when I was early on in my analysis, I was skeptical about exactly how the “big data” business works, but it turns out it is substantially worse than I could have imagined. A takeaway I am leaving with is that technology is not about what can be done, it is more what should be done. It is not enough for businesses to create new technologies to make our lives easier, it should always be balanced with what is safe, ethical, and the morally correct thing to do. Privacy is one of the last layers we have against society, and it should be protected at all costs.
Within module 4 I tackled the utilitarian perspective on the ethics of software development. This topic was particularly interesting because it truly opened my eyes to the possibility that there are many businesses who do not take the ethical and moral approach to development operations (devops), especially when it comes to generating profits. My analysis concluded that both the software developer and the business that hired them were unethical in their practice of designing a test that leads to the pharmaceutical product being advertised, regardless of quiz results. The takeaway from this lesson is that profits should never outweigh the responsibility to protect their consumers, or the public at large. Software developers have a moral obligation to ensure the codes they write are ethical, and free of unfare bias.
Lastly, in module 6 I conducted a case analysis involving the ethical and moral dilemmas associated with cyberwarfare in modern war. This one was particularly challenging due to the subject matter being incredibly nuanced and relevant to today’s geopolitical landscape. For this analysis, I used the perspective of the utilitarian, similarly to module 4. Among all of the many academic resources provided in module 6, it seemed fairly clear that cyberwarfare was incredibly difficult to contain and supervise. From the utilitarian perspective, cyberwarfare required a substantial amount of “buy-in” in order to determine whether or not the attack’s benefits outweighed the cost. This was increasingly difficult to measure simply because a cyber attack is typically large-scale due to everything being connected in one way or another, via the internet. One thing I would like to remind my future self of is that just because an action may provide a temporary strategic advantage, it does not necessarily mean that it is automatically and ethically justified. Many things can go wrong (and they often do) when it comes to cyber warfare, and it is ultimately the civilian population that will pay the price.
Overall, this course has been an extremely eye-opening experience. While it is easy to sit and read these articles, it is an entirely different experience when it comes to applying ethical and moral analysis on the many pieces that comprise the cyber field. I look forward to continuing my education within cybersecurity, and applying these ethical tools as I continue to involve myself within the profession, and within the private sector.