Unformatted text preview: owth of research—teach, mentor, and value the certification.
• Discourage unnecessary fear or doubt, and do not consent to bad practices.
• Discourage unsafe practices, and preserve and strengthen the integrity of
public infrastructures. ch10.indd 906 12/4/2009 11:39:13 AM All-in-1 / CISSP All-in-One Exam Guide, 5th Ed. / Harris / 160217-8 Chapter 10: Legal, Regulations, Compliance, and Investigations 907
• Observe and abide by all contracts, expressed or implied, and give prudent advice.
• Avoid any conflict of interest, respect the trust that others put in you, and take
on only those jobs you are fully qualified to perform.
• Stay current on skills, and do not become involved with activities that could
injure the reputation of other security professionals.
An interesting relationship exists between law and ethics. Most often, laws are based
on ethics and are put in place to ensure that others act in an ethical way. However, laws
do not apply to everything—that is when ethics should kick in. Some things may not
be illegal, but that does not necessarily mean they are ethical.
Corporations should have a guide developed on computer and business ethics. This
can be part of an employee handbook, used in orientation, posted, and made a part of
Certain common ethical fallacies are used by many in the computing world to justify their unethical acts. They exist because people look at issues differently and interpret (or misinterpret) rules and laws that have been put into place. The following are
examples of these ethical fallacies:
• Hackers only want to learn and improve their skills. Many of them are not
making a profit off of their deeds; therefore, their activities should not be seen
as illegal or unethical.
• The First Amendment protects and provides the right for U.S. citizens to write
• Information should be shared freely and openly; therefore, sharing
confidential information and trade secrets should be legal and ethical.
• Hacking does not actually hurt anyone. The...
View Full Document