<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Teaching ethics? in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15777#M1776</link>
    <description>&amp;gt; Shannon (Contributor II) posted a new reply in Industry News on 10-22-2018 09:02 PM in the (ISC)Â² Community :&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Letâ&amp;#128;™s face it --- while CISSPs are bound to hold up the code of ethics,&lt;BR /&gt;&amp;gt; they arenâ&amp;#128;™t always enforced to do so by legal organizations, and so their&lt;BR /&gt;&amp;gt; boundaries will vary with the environment.&lt;BR /&gt;&lt;BR /&gt;You've probably all heard the "laws of combat" that float around. My favourite is&lt;BR /&gt;"Look unimportant: the enemy may be low on ammunition." As corollary, I&lt;BR /&gt;usually point out that one of the best ways not to become a target is not to be&lt;BR /&gt;evil. (I suppose I should reword that these days, since Google seems to be&lt;BR /&gt;departing from that mantra ...)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; An example: Jack is a CISSP,&lt;BR /&gt;&amp;gt; holding an executive position in a business-driven&amp;nbsp;organization&amp;nbsp;that&lt;BR /&gt;&amp;gt; offers&amp;nbsp;IT Solutions&amp;nbsp;&amp;amp;&amp;nbsp;Services.&lt;BR /&gt;&lt;BR /&gt;The biggest cause of IT problems is IT "solutions."&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Should Jack want to veto or implement any&lt;BR /&gt;&amp;gt; major process, the final decision falls to a board of directors.&lt;BR /&gt;&lt;BR /&gt;We all know that ethics is definitely "top-down" in any enterprise. If you are&lt;BR /&gt;fighting senior management on ethical issues, it is time to quit. "Grassroots"&lt;BR /&gt;ethical change just does not seem to work (although there have been some isolated&lt;BR /&gt;cases recently that might give one hope).&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Before you ask to&amp;nbsp;what&amp;nbsp;level I&lt;BR /&gt;&amp;gt; stand up for ethics in my organization,&amp;nbsp;let me&amp;nbsp;tell you that&amp;nbsp;it's&amp;nbsp;in&lt;BR /&gt;&amp;gt; KSA...&lt;BR /&gt;&lt;BR /&gt;I rest my case ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;I don't yet have a solution, but I have a new name for the&lt;BR /&gt;problem. - Ross A. Leo, CISSPforum, 20050712&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Tue, 23 Oct 2018 19:06:00 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2018-10-23T19:06:00Z</dc:date>
    <item>
      <title>Teaching ethics?</title>
      <link>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15743#M1774</link>
      <description>&lt;P&gt;Well, we've talked about &lt;A href="https://community.isc2.org/t5/Welcome/Ethical-principals/m-p/13068" target="_blank"&gt;mispeling ethical principals&lt;/A&gt;, and the &lt;A href="https://community.isc2.org/t5/Member-Support/Code-of-Ethics-and-Protests/m-p/4047" target="_blank"&gt;ethics of protests&lt;/A&gt;, but the New York Times has an interesting opinion piece on the &lt;A href="https://www.nytimes.com/2018/10/21/opinion/who-will-teach-silicon-valley-to-be-ethical.html" target="_blank"&gt;need for ethics in technology companies&lt;/A&gt; at large.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:59:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15743#M1774</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T08:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Teaching ethics?</title>
      <link>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15758#M1775</link>
      <description>&lt;P&gt;Let’s face it --- while CISSPs are bound to hold up the code of ethics, they aren’t always enforced to do so by legal organizations, and so their boundaries will vary with the environment.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;An example: Jack is a CISSP, holding an executive position in a business-driven&amp;nbsp;organization&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that offers&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;IT Solutions&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;amp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Services. Should Jack want to veto or implement any major process, the final decision falls to a board of directors. When&amp;nbsp;presenting business cases with a cost-benefit&amp;nbsp;and&amp;nbsp;risk analysis,&amp;nbsp;he has to&amp;nbsp;keep in mind that&amp;nbsp;the directors&amp;nbsp;won't consider morality in place of money.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Assuming&amp;nbsp;he can link his cases to other factors that impact the&amp;nbsp;business --- say, legal implications --- he&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;might&amp;nbsp;get heads&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;turn;&amp;nbsp;otherwise, no.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If&amp;nbsp;he's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;too strong an advocate of ethics &amp;amp;&amp;nbsp;it&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;doesn't appeal to the directors, they may&amp;nbsp;decide to let him go, &amp;amp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;should this happen, there’s no guarantee he’ll be able to find a new post&amp;nbsp;with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;equal&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;/ higher&amp;nbsp;benefits.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Of course,&amp;nbsp;he’ll&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;probably have better luck if he's employed by (ISC)2&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before you ask to&amp;nbsp;what&amp;nbsp;level I stand up for ethics in my organization,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;let me&amp;nbsp;tell you that&amp;nbsp;it's&amp;nbsp;in KSA...&amp;nbsp;&amp;nbsp;&lt;img id="manwink" class="emoticon emoticon-manwink" src="https://community.isc2.org/i/smilies/16x16_man-wink.png" alt="Man Wink" title="Man Wink" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 01:02:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15758#M1775</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-10-23T01:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Teaching ethics?</title>
      <link>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15777#M1776</link>
      <description>&amp;gt; Shannon (Contributor II) posted a new reply in Industry News on 10-22-2018 09:02 PM in the (ISC)Â² Community :&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Letâ&amp;#128;™s face it --- while CISSPs are bound to hold up the code of ethics,&lt;BR /&gt;&amp;gt; they arenâ&amp;#128;™t always enforced to do so by legal organizations, and so their&lt;BR /&gt;&amp;gt; boundaries will vary with the environment.&lt;BR /&gt;&lt;BR /&gt;You've probably all heard the "laws of combat" that float around. My favourite is&lt;BR /&gt;"Look unimportant: the enemy may be low on ammunition." As corollary, I&lt;BR /&gt;usually point out that one of the best ways not to become a target is not to be&lt;BR /&gt;evil. (I suppose I should reword that these days, since Google seems to be&lt;BR /&gt;departing from that mantra ...)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; An example: Jack is a CISSP,&lt;BR /&gt;&amp;gt; holding an executive position in a business-driven&amp;nbsp;organization&amp;nbsp;that&lt;BR /&gt;&amp;gt; offers&amp;nbsp;IT Solutions&amp;nbsp;&amp;amp;&amp;nbsp;Services.&lt;BR /&gt;&lt;BR /&gt;The biggest cause of IT problems is IT "solutions."&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Should Jack want to veto or implement any&lt;BR /&gt;&amp;gt; major process, the final decision falls to a board of directors.&lt;BR /&gt;&lt;BR /&gt;We all know that ethics is definitely "top-down" in any enterprise. If you are&lt;BR /&gt;fighting senior management on ethical issues, it is time to quit. "Grassroots"&lt;BR /&gt;ethical change just does not seem to work (although there have been some isolated&lt;BR /&gt;cases recently that might give one hope).&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Before you ask to&amp;nbsp;what&amp;nbsp;level I&lt;BR /&gt;&amp;gt; stand up for ethics in my organization,&amp;nbsp;let me&amp;nbsp;tell you that&amp;nbsp;it's&amp;nbsp;in&lt;BR /&gt;&amp;gt; KSA...&lt;BR /&gt;&lt;BR /&gt;I rest my case ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;I don't yet have a solution, but I have a new name for the&lt;BR /&gt;problem. - Ross A. Leo, CISSPforum, 20050712&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 23 Oct 2018 19:06:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15777#M1776</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-10-23T19:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Teaching ethics?</title>
      <link>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15790#M1777</link>
      <description>&lt;P&gt;Google didn't fully retire that slogan, they simply dropped the 'don't', as it was considered too negative...*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For senior leadership fights on ethics one can look at the debacle in Yahoo:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html" target="_self"&gt;https://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theguardian.com/technology/2017/mar/02/yahoo-boss-marissa-meyer-loses-millions-in-bonuses-over-security-lapses" target="_self"&gt;https://www.theguardian.com/technology/2017/mar/02/yahoo-boss-marissa-meyer-loses-millions-in-bonuses-over-security-lapses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nypost.com/2017/11/08/marissa-mayer-testimony-i-dont-know-how-yahoo-hack-happened/" target="_self"&gt;https://nypost.com/2017/11/08/marissa-mayer-testimony-i-dont-know-how-yahoo-hack-happened/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theguardian.com/books/2015/jan/05/marissa-mayer-and-fight-to-save-yahoo-review" target="_self"&gt;https://www.theguardian.com/books/2015/jan/05/marissa-mayer-and-fight-to-save-yahoo-review&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href=" https://www.bloomberg.com/features/2016-marissa-mayer-interview-issue/" target="_self"&gt;https://www.bloomberg.com/features/2016-marissa-mayer-interview-issue/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ballardspahr.com/alertspublications/articles/2018-05-11-yahoo-data-breach.aspx" target="_self"&gt;https://www.ballardspahr.com/alertspublications/articles/2018-05-11-yahoo-data-breach.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theregister.co.uk/2018/04/24/yahoo_fined_35m/" target="_blank"&gt;https://www.theregister.co.uk/2018/04/24/yahoo_fined_35m/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I realize that a lot of linkspam... so my take on it as a TL;DR is that the leadership was bent out of shape and didn't feel the Solyent Green required it's information to be protected, at least not having actual money spent on it. It's telling on a few fronts that a CEO would publicly signal that 130 hour work weeks are possible and can be managed (yes they are, they are not good and an ethical CEO probably wouldn't put the idea out there) , and frankly it will distort your moral compass, and you might start hallucinating), the head of legal took the fall for it and all that happened to the CEO was lost compensation, I do wonder if we will see more accountability in the world of GDPR and the FTC sharpening it's claws.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* I realize I may have used this line before, but jokes should be considered consumer durable for as long as you can get away with it due to ethical concerns about the heavy environmental impact of joke creation...&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 23:39:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Teaching-ethics/m-p/15790#M1777</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-10-23T23:39:37Z</dc:date>
    </item>
  </channel>
</rss>

