Ethics
Home Reports

Informatics Research Institute

Up
ISSA Ethics
ISACA Ethics
ACM Ethics
ISTE Ethics
IEEE Ethics
IAP Behavior
Williams College

The Idaho State University Information Assurance program recognizes the importance of an ethical foundation of behavior.

One code of ethics that we propose all participants adhere to is that from (ISC)2, the International Information Systems Security Certifying Consortium.

(ISC)2 Code of Ethics

"All information systems security professionals who are certified by (ISC)2 recognize that such certification is a privilege that must be both earned and maintained. In support of this principle, all Certified Information Systems Security Professionals (CISSPs) commit to fully support this Code of Ethics. CISSPs who intentionally or knowingly violate any provision of the Code will be subject to action by a peer review panel, which may result in the revocation of certification.

There are only four mandatory canons in the code. By necessity such high-level guidance is not intended to substitute for the ethical judgment of the professional.

Additional guidance is provided for each of the canons. While this guidance may be considered by the Board in judging behavior, it is advisory rather than mandatory. It is intended to help the professional in identifying and resolving the inevitable ethical dilemmas that will confront him/her.

Code of Ethics Preamble:

bullet

Safety of the commonwealth, duty to our principals, and to each other requires that we adhere, and be seen to adhere, to the highest ethical standards of behavior.

bullet

Therefore, strict adherence to this code is a condition of certification.

 

Code of Ethics Canons:

  1. Protect society, the commonwealth, and the infrastructure.

  2. Act honorably, honestly, justly, responsibly, and legally.

  3. Provide diligent and competent service to principals.

  4. Advance and protect the profession.

The following additional guidance is given in furtherance of these goals.

Objectives for Guidance

In arriving at the following guidance, the committee is mindful of its responsibility to:

Give guidance for resolving good v. good and bad v. bad dilemmas.

To encourage right behavior such as:

bullet

Research

bullet

Teaching

bullet

Identifying, mentoring, and sponsoring candidates for the profession

bullet

Valuing the certificate

bullet

To discourage such behavior as:
bullet

Raising unnecessary alarm, fear, uncertainty, or doubt

bullet

Giving unwarranted comfort or reassurance

bullet

Consenting to bad practice

bullet

Attaching weak systems to the public net

bullet

Professional association with non-professionals

bullet

Professional recognition of or association with amateurs

bullet

Associating or appearing to associate with criminals or criminal behavior

However, these objectives are provided for information only; the professional is not required or expected to agree with them.

In resolving the choices that confront him, the professional should keep in mind that the following guidance is advisory only. Compliance with the guidance is neither necessary nor sufficient for ethical conduct.

Compliance with the preamble and canons is mandatory. Conflicts between the canons should be resolved in the order of the canons. The canons are not equal and conflicts between them are not intended to create ethical binds.

Protect society, the commonwealth, and the infrastructure

bullet

Promote and preserve public trust and confidence in information and systems.

bullet

Promote the understanding and acceptance of prudent information security measures.

bullet

Preserve and strengthen the integrity of the public infrastructure.

bullet

Discourage unsafe practice.

 

Act honorably, honestly, justly, responsibly, and legally

bullet

Tell the truth; make all stakeholders aware of your actions on a timely basis.

bullet

Observe all contracts and agreements, express or implied.

bullet

Treat all constituents fairly. In resolving conflicts, consider public safety and duties to principals, individuals, and the profession in that order.

bullet

Give prudent advice; avoid raising unnecessary alarm or giving unwarranted comfort. Take care to be truthful, objective, cautious, and within your competence.

bullet

When resolving differing laws in different jurisdictions, give preference to the laws of the jurisdiction in which you render your service.

 

Provide diligent and competent service to principals

bullet

Preserve the value of their systems, applications, and information.

bullet

Respect their trust and the privileges that they grant you.

bullet

Avoid conflicts of interest or the appearance thereof.

bullet

Render only those services for which you are fully competent and qualified.

 

Advance and protect the profession

bullet

Sponsor for professional advancement those best qualified. All other things equal, prefer those who are certified and who adhere to these canons. Avoid professional association with those whose practices or reputation might diminish the profession.

bullet

Take care not to injure the reputation of other professionals through malice or indifference.

bullet

Maintain your competence; keep your skills and knowledge current. Give generously of your time and knowledge in training others

 

All material on this site is copyright unless otherwise noted.
Please respect the authors rights by requesting permission for use and ensuring proper attribution and credit.