Legal Issues
Data Protection Act 1998
This is a legislation that is designed to protect personal data that is stored on computers or a paper filing system. The office of the Information Commissioner will charge companies a small fee for them to hold an individual's information. Anybody whom has their information protected with this act has the right to find out what information is held against them.The legislation covers the 8 main principles of how to store and process data:
- It must be collected and used fairly and inside the law.
- It must only be obtained for one or more specified reasons.
- It must be adequate, relevant and not excessive in relations to the purpose collected.
- It must be adequate, and up to date.
- It must not be kept for longer than necessary for the purposes specified.
- It must be processed within the rights of an individual.
- It has to be secure within the organisation.
- Personal data cannot be transferred to a country or territory outside of the EEA unless the country has adequate protection.
A low risk of Data Protection might be if a company uses data for another reason than the specified reason. An example of this is if a company wanted to use a customer's details for marketing reasons for a product, the company might then think a customer might be interested in working for that company.
Computer Misuse Act 1990
This is a legislation that is designed to protect users against attack and theft of their information.Offences under the act include; hacking, data misuse, copying and distributing software like music and films, email and chat room abuses, pornography, identity and financial abuses and viruses.
The company should provide training to anybody who has access to the online data. They should also make sure that data is secure, and that people are only viewing it who have the permission to do so. Passwords should be made secure and therefore have a mixture of both letters, numbers and symbols, along with lowercase and capital letters.
The DOS (Denial Of Service) attack stops users from using the computing through disabling ports, increasing network traffic, to slow down or stop access.
Three new offences were made and recognized by parliament:
- Unauthorized access to any computer program or data: using somebody's login and password.
- Unauthorized access with intent to commit a serious crime.
- Unauthorized modification of computer contents.
A high risk of a Computer Misuse is unauthorised access and modification of computer contents, this could be changing the content on a network or blocking other users accessing a webpage or source. This could also be if somebody was to take down a webpage.
A low risk of a Computer Misuse is unauthorised access to any computer program or data. An example of this is, if a user left their computer unlocked and it was accessed by someone else, and documents were modified and accounts were accessed.
Ethical Issue
Whistleblowing
A whisleblower is somebody who reports wrongdoing in their workplace. If somebody decides to raise their concern they should keep a copy of their organisations whistleblowing policy and then seek advice.
If you are an employee, a trainee or an agency worker you are protected by the government after reporting a wrongdoing.
There are several complaints that count as whistleblowing, below i will list them:
- A criminal offence e.g. fraud
- Somebody's health or safety is in danger
- Risk/actual damage to the environment
- A miscarriage of justice
- The company is breaking the law e.g. incorrect insurance
- Somebody is covering up wrongdoing in the workplace
A whistleblower should always speak up if they believe that one of the above activity is happening.
However this can sometimes lead to isolation and humiliation.
Whistleblowing protects computer users who draw the management's attention to other's misuse on the system. To reduce the risk of misuse taking place in a working environment, IT administrators can run the server to detect any misuse first.
Whistleblowing protects computer users who draw the management's attention to other's misuse on the system. To reduce the risk of misuse taking place in a working environment, IT administrators can run the server to detect any misuse first.
A high risk of whistleblowing is if the company does not have a policy in place to protect them from reporting wrongdoing in the workplace.
A low risk of whistleblowing is if somebody who witnessed a wrongdoing did not report it. For example, if somebody saw another stealing stock and they didn't report it this would be a low risk because nobody would be in physical danger.
Information Ownership
Information ownership is the legal right of having ownership over a single piece or set of data elements.
If a company has ownership over data, they should maintain it and look after it. Some companies have an information ownership policy or set of guideline for its employees. Non-disclosure agreements are signed by employees where they promise to not share company information outside of the workplace.
It is important that each employee within a company should assign different parts of data to another department this will help to reduce the amount of incorrect information and it will also help to maintain it.
A high risk example of information ownership is if an employee copied any information that is supposedly meant to be protected by a non-disclosure agreement.
A low risk example of information ownership is if the information hasn't been updated in a week, it could contain out of date information, spelling errors or missing data.
If a company has ownership over data, they should maintain it and look after it. Some companies have an information ownership policy or set of guideline for its employees. Non-disclosure agreements are signed by employees where they promise to not share company information outside of the workplace.
It is important that each employee within a company should assign different parts of data to another department this will help to reduce the amount of incorrect information and it will also help to maintain it.
A high risk example of information ownership is if an employee copied any information that is supposedly meant to be protected by a non-disclosure agreement.
A low risk example of information ownership is if the information hasn't been updated in a week, it could contain out of date information, spelling errors or missing data.
Operational Issues
Security of information
Security of information is the practice of preventing any unauthorised access.This is used for electronic and physical data.
The management will decide what information can be viewed with other users, and they will keep logs of which users have viewed what information. There are authorisation and administration rights in place to make sure the policy is followed.
A high risk example of the security of information is if the management team do not have any security in place to keep the information protected.
A low risk example of security of information is if the information is not backed-up, therefore it would be lost and would be unable to be retrieved.
Health & Safety
Health & Safety are regulations and procedures that are in place by a company to help prevent an accident or injury.
To follow the health and safety regulations/procedures the company could provide employees with training and leave information sheets around the workplace for further instruction. There are also environment laws in place.
Health & Safety training can have a cost if the employees have to take a day off work for external training. To prevent an accident or injury taking place each employee should take regular breaks. If an employee has any issues with their eyesight then they should have regular check ups.
In an office environment all cables that are connected to the computer and monitor should be tucked away or covered using a cable cover.
A high risk example of health and safety is if the regulations and procedures within the company aren't followed, this can increase the risk of an accident or injury.
A low risk example of health and safety is if minor accidents aren't reported and followed up. E.g. Somebody could slip over on a wet floor and crack their head open, and there weren't any yellow warning signs around the area to express the danger.