IT Security ethics: How does ethics work in Information Security? New research reveals that 20% of personnel in the industry have witnessed a breach being covered up.
In a survey by AlienVault, when asked, “What course of action do you think is best when a company is breached?” 9% responded, “If no one knows, it’s just better to just keep quiet.”
Two-thirds of respondents would use the breach as an opportunity to persuade the board to approve additional security safeguards, while a quarter would go further, accepting the breach as part of their job. However, a not inconsiderable 6.6% said they would admit the incident to the media, and brag about how the breach could have been avoided if the company had followed the security measures suggested.
[blockquote]“This is an interesting perspective on how most organizations operate. It takes one more breach to get funding to increase security. The inability of IT security professionals to communicate needs to the business and rely on breaches to succeed is a burning issue that doesn’t look like it will be resolved anytime soon,”
says Javvad Malik, of AlienVault.
The survey also found that most believe that the chief IT Security officer should be held accountable for the breach, if it actually comes to light.
More than half of security experts monitor hacker forums to stay up to date on the latest threats and technologies.
In various ways, the IT Security as a profession emerged from the hacking, which introduced new activities, which led to the need to establish a legal framework and to distinguish activities as acceptable and unacceptable by law, as aptly stated in the research.
The report also examines the issue of breach responsibility: A breach in a company often degenerates into a blame game over who should be held accountable. More than a third of respondents in the survey (38.3%) believe that the CISO should take responsibility in the event of an incident. Around 25% believe that the CEO, CIO and VP of IT Security of the company should be equally accountable. Interestingly, 10% also believe that responsibilities should be assigned to the board of directors.
In general, it is clear that work is clearly needed on the ethics front in the IT security industry.

