Format all references according to APA guidelines, and images must not be copied unless author permission is obtained or copyright free images are used

profileMichelle_Michy
20200702224536cyb320_week3_ethicalchallenges_ad_6_22_20.docx

Learning Team – Ethical Challenges Worksheet - Week Three

Your team of international developers will be developing a publicly-accessible cloud-based application which may potentially house user PII data, information about user’s behavior and activities (e.g., physical locations, online sites they visit, searches, purchases, etc.), and user’s intellectual property (e.g., photos, artwork, videos, etc.).

Continue your work on the features of the app by specifying the type of data the feature uses, a risk mitigation strategy for the risk you provided in Week Two, and a global ethical perspective of the choices you made in implementing a risk mitigation strategy.

Features of the App

Data Requirement

What ethical challenges does the feature present?

What risk does the feature present?

Risk Mitigation Strategy

Global perspective and Commonality of Ethical Choice

< From Week Two - For example, housing PII data>

<Indicate the type of data involved>

<From Week Two - Does the feature itself present a challenge, or would protecting it or assessing it present a challenge?>

< From Week Two - Explain what you would think a potential risk could be>

<What security mitigation strategy could you provide to mitigate the risk (e.g., encrypt the data)?>

A potential risk for storage of PII data, is data loss by any means, to include failure of a server, security breach, etc.(Achille)

<Does your security decision depend on your perspective on rights to privacy or human rights or culture, etc., or does your security mitigation strategy transcend cultures?>

The use of encryption and multi-factor actually enhances the individuals rights to privacy and ensures that any of their basic human rights are protected. These types of security transcend cultures as far as security goes.( Achille)

Customer consent collecting PII / Do not track option

Health Statistics such as blood pressure, heart rate, stress level, etc. /

Fitness Trackers

(Do not track option)

Protecting PII data would present a challenge: options for users to choose how their data is used (on-site personalization, marketing, etc.)

If user chose not to use tracking features or chose to use features accordingly, the app would need to be privacy compliant from 3rd parties that may use tags.

Data Anonymization (by means of hashing algorithms):

Data processing techniques which remove or modify PII data.

Rights to privacy:

Gives users more control over their PII and follows the various laws around the world protecting user privacy.

Gathers all single organization stores and uses

PII

All customers consent must be obtained unless the data is being processed in a strict medical context.

Developed an app to protect people's privacy and data while on and off the app.

Privacy act, things like the protect the privacy and confidentiality of the organization, apps may transmit that data and over unsecure network.

Data Anonymization (by means of hashing algorithms):

Data processing techniques which remove or modify PII data.

Rights to privacy:

Gives organization more control over their PII and follows the various laws around the world protecting user privacy.

Employee Consent collecting and using Pll

(Allow employees the option to Opt-In or Opt-Out of Alpha or Beta Stages)

By allowing customers the option of either consenting or dismissing the option to collect and use their personal data would deem this an acceptable global ethic. This is because an alternative option is available (disabled option), the goal is to help people, and we are doing what we believe to be right.

Protecting PII data would present a challenge: options for users to choose how their data is used (on-site personalization, marketing, etc.)

Does confidentiality options prevent cookies from being used?

By authorizing consent your information could be obtained by someone who is not authorized depending on the security of the network.

Data Anonymization (by means of hashing algorithms):

Data processing techniques which remove or modify PII data.

2nd opinion**

We could add some type of dual authentication when requesting personal information.

Rights to privacy:

Gives employees more control over their PII and follows the various laws around the world protecting user privacy.