Information Technology Incident Report and Summary (Twitter Incident)
IT 659 Final Project Guidelines and Rubric
Overview The final project for this course is the creation of an information technology incident report. Successful management in information technology requires knowledge of the legal and ethical environment. Globalization, increasing commerce between graphical locations brought on by the ability to connect online, and the i ncreasing mix of cultures bring additional complexity to the considerations of law and ethics in cyber security and information technology (IT). The final project for this course will require you to research a recent (within the last five years) incident or event in the field of IT, e-commerce, or cyber security in the context of the legal and ethical standards of that time period. You will identify the issues the organization(s) had, recommend changes for that organization(s), and write a report that highlights your recent analysis, findings, and recommendations. The project is divided into three milestones, which will be submitted at various points throughout the course to scaffold learning and ensure quality final submissions. These milestones will be submitted in Modules Two, Four, and Seven. The final submission will occur in Module Nine. In this assignment you will demonstrate your mastery of the following course outcomes:
Apply cyberlaw principles appropriately to everyday circumstances, business models, and information technology issues
Assess legal and compliance issues related to information technology for their impact to organi zations, society, and culture
Propose relevant changes to organizations and standards that ensure legal and ethical cyber practice and behavior Determine the impact of various legal cases on compliance and regulatory standards within information technolog y
Analyze the impact of various cultural attitudes and legal issues related to global communication on information technology
Prompt You will select a recent or current incident from the public record and analyze the case to identify the issues that led to the incident. What recommendations can you make to ensure the incident will not occur again? What were the results of the incident? And, finally, what were the cultural, societal, or global impacts of this case and the subsequent changes to the legal environment? Please note: Your selection will need to be submitted and approved by the instructor. Specifically the following critical elements must be addressed:
I. Introduction a) Apply cyberlaw and security principles to the business, e-commerce, and e-communication industries. What purpose does the application of
cyber principles serve for these industries? b) Summarize the selected case, including the necessary organizational information, industry, problem, and time period of the incident.
II. Case Analysis a) Analyze the case to determine the ethical issues within the organization that may have led to the incident. What are these issues and why do
you credit them for the incident? b) Determine legal compliance issues within the organization that may have led to the incident or could lead to future incidents. Were there any
legal and ethical standards in existence at the time that were not followed by the organization? What were these issues and h ow did they impact the organization?
c) Determine the societal and cultural impact of these compliance issues. Some things to consider in your assessment include specific targeting of demographic groups, victimization of certain customers, and so on.
III. Incident Impact a) Determine the impact this incident may have had on the ethical and legal IT regulations of the time. If there were no direct results of this case,
what may have been the indirect impact and/or what was the impact of similar cases? For example, what regulatory changes resu lted from this or similar cases? What is your reasoning?
b) Determine the connection between the industry standards and the standards in existence for information technology. Specifically, determine if the organization was lacking in either industry-specific or IT-specific alignment with regulations that may have contributed to the incident, and provide support for your conclusions. For example, misalignment with HIPAA laws in healthcare is an industry-specific deviation from standards.
c) Cultural Impact: Analyze the influence this incident may have had on various cultural attitudes toward IT and cyber communication or commerce. In other words, how could this incident impact views of information technology use ?
IV. Recommendations a) Propose relevant changes to the organization that may have prevented the incident. How would these changes have helped to prevent the
occurrence? b) Propose reasonable ethical guidelines that could have helped prevent the incident and that might help the organization prevent future
incidents. c) Propose changes to the standards external to the organization that might have helped prevent the incident. This can include changes to
regulations and regulatory and ethical standards that might exist today but did not exist or were not properly delivered at the time of the incident. Be sure to support your conclusions.
V. Global Considerations a) What international compliance standards (either at the time of the incident or today) would have been relevant to the incident, and how? If
your company is not global, imagine that is. b) Analyze the impact of the incident on global communication and commerce (again, if your organization is not global, imagine otherwise). In
other words, what impact did (or would) the incident have on views and use of information technology and communication in glo bal contexts? c) Global Technology Environment: Based on your research and analysis of this case, determine the global legal and regulatory impacts this case
had on the information technology overall. In other words, determine the relationship between this case and the global regula tory standards that are now in place, will be put in place shortly, or should be put in place as a result of this or related incident(s).
VI. Summary: Given your knowledge of cyberlaw principles, ethical needs, and legal compliance standards, summarize how you applied t hese principles to your analysis of the case. In other words, how did you apply cyberlaw principles to the circumstances, business model, and IT issues that the selected organization faced?
Milestones Milestone One: Introduction In Module Two, you will submit the introduction. In this assignment you will identify the cyberlaw principles and explain how each applie s to the business, e- commerce, or e-communication industries chosen. Describe the purpose of the application of the pri nciples serve for the industry. You will also need to include the necessary organizational information, industry, problem, and the time period of the incident that occurred. The format of this assignment will be a one- to two-page Word document. This milestone is graded with the Milestone One Rubric. Milestone Two: Case Analysis and Incident Impact In Module Four, you will submit the Case Analysis and Incident Impacts. In this assignment you will analyze the ethical issues and determine the legal compliance issues within the organization as well as the social and cultural impacts of these compliance issues. You will be expected to address the impact the incident may have had on the ethical and legal IT regulations at the time. The connection between the industry standards and the standards for informational technology should be determined, as well as the influence of the cultural impact to IT and cyber communication or commerce. The format of this assignment will be a three- to five-page Word document. This milestone is graded with the Milestone Two Rubric. Milestone Three: Recommendations and Global Considerations In Module Seven, you will submit the Recommendations and Global Considerations. In this assignment you will suggest relevant changes to the organi zation itself and changes to the ethical guidelines that could have prevented the incident. Standards external to the organization t hat may have helped prevent the incident should also be proposed. This assignment will also address international compliance standards and how they would have been relevant to the incident. The impact of the incident on global communication and commerce will be analyzed , as well as the impact on the global technology environment. The format of this assignment will be a three- to five-page Word document. This milestone is graded with the Milestone Three Rubric. Final Submission: Information Technology Incident Report and Summary In Module Nine, you will submit your Information Technology Incident Report along with a summary explaining how you applied the principles to your analysis of the case. It should be a complete, polished artifact containing all of the critical elements of the final product. It should reflect the incorporation of feedback gained throughout the course. This submission will be graded using the Final Product Rubric.
Deliverables
Milestone Deliverable Module Due Grading
1 Introduction Two Graded separately; Milestone One Rubric
2 Case Analysis and Incident Impact Four Graded separately; Milestone Two Rubric
3 Recommendations and Global Considerations
Seven Graded separately; Milestone Three Rubric
Final Submission: Information Technology Incident Report and Summary
Nine Graded separately; Final Product Rubric
Final Product Rubric Guidelines for Submission: Your report should be long enough to contain all relevant information, reasoning, and research. It should be formatted logica lly and written in a professional manner, following APA guidelines.
Critical Elements Exemplary (100%) Proficient (90%) Needs Improvement (70%) Not Evident (0%) Value
Introduction: Application of Cyber
Principles
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the
nuanced purpos e of cyber pri nci pl es i n mul ti pl e i ndus tries
Accuratel y appl i es cyber pri nci pl es to the bus i nes s , e-
commerce, and e- communi cati on i ndus tri es to expl ai n the purpos e s erved by
the pri nci pl es
Appl i es cyber pri nci ples to bus i nes s , e-commerce, and e-
communi cati on but wi th gaps i n accuracy or wi thout detai l regardi ng the purpos e s erved
by thes e pri nci ples
Does not appl y cyber pri nci pl es to bus i nes s , e-commerce, and
e-communi cati on
6.5
Introduction: Summary of Case
Meets “Profi ci ent” cri teri a , and qual i ty of i ntroducti ons es tabl i s hes experti s e i n the di s ci pline
Comprehens i vel y and conci s el y i ntroduces the s el ected i nci dent wi th neces s ary organi zational i nformati on, the i ndus try type,
the probl em, and the ti me peri od of occurrence
Introduces the s el ected i nci dent wi th organi zati onal i nformation, the i ndus try type, the probl em, and the ti me peri od of
occurrence, but l acks neces s ary detai l or i ncl udes s uperfl uous i nformati on
Does not i ntroduce the s el ected i nci dent wi th organi zati onal i nformati on, the i ndus try type, the probl em, and the ti me
peri od of occurrence
6.5
Case Analysis: Ethical Issues
Meets “Profi ci ent” cri teri a , and reas oni ng evi dences s trong
ethi cal cri teri a or keen anal yti c s ki l ls regarding organizati onal ethi cs
Accuratel y anal yzes the cas e to determi ne whi ch ethi cal i s sues
wi thi n the organi zati on l ed to the i nci dent, and why
Anal yzes the cas e to determi ne whi ch ethi cal i s s ues wi thi n the
organi zati on l ed to the i nci dent, and why, but wi th gaps i n accuracy or detai l
Does not anal yze the cas e to determi ne whi ch ethi cal i s sues
wi thi n the organi zati on l ed to the i nci dent, and why
6.5
Case Analysis: Legal Compliance
Meets “Profi ci ent” cri teri a and evi dences keen unders tandi ng
of l egal cri teri a of the ti me
Accuratel y determi nes the l egal compl i ance i s s ues wi thi n the
organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues
Determi nes the l egal compl i ance i s s ues wi thi n the
organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues , but wi th gaps i n accuracy or detai l
Does not determi ne the l egal compl i ance i s s ues wi thi n the
organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues
6.5
Case Analysis:
Societal and Cultural Impact
Meets “Profi ci ent” cri teri a and
evi dences deep i ns i ght i nto unexpected, hi dden, or compl ex i mpacts on cul ture and s oci ety
Comprehens i vel y and
accuratel y determi nes the s oci etal and cul tural i mpacts of the l egal and ethi cal compl i ance i s s ues
Determi nes the s oci etal and
cul tural i mpacts of the l egal and ethi cal compl i ance i s sues , but wi th gaps i n accuracy or detai l
Does not determi ne the s oci etal
and cul tural i mpacts of the l egal and ethi cal compl i ance i s sues
6.5
Incident Impact:
Regulations
Meets “Profi ci ent” cri teri a and
evi dences keen unders tandi ng of ethi cal and l egal regul ati ons fol l owi ng the i nci dent
Accuratel y determi nes the
di rect or i ndi rect i mpact of thi s or s i mi l ar case on ethi cal and l egal IT regul ati ons at the ti me
Determi nes the di rect or
i ndi rect i mpact of thi s or s i mi l ar cas e on ethi cal and l egal IT regul ati ons at the ti me, but wi th gaps i n accuracy or l ogi cal
reas oni ng
Does not determi ne the di rect
or i ndi rect i mpact of thi s or s i mi l ar case on ethi cal and l egal IT regul ati ons at the ti me
6.5
Incident Impact: Standards
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto unders tandi ng and appl yi ng IT
and i ndus try-s peci fi c s tandards for i nformati on s ecuri ty
Accuratel y determi nes the connecti on between i ndus try s tandards and s tandards i n
exi s tence for i nformati on technol ogy wi th l ogi cal reas oni ng and s upport
Determi nes the connecti on between the i ndus try s tandards and the s tandards i n exi s tence
for i nformati on technol ogy, but wi th gaps i n accuracy or gaps i n reas oni ng and s upport
Does not determi ne the connecti on between the i ndus try s tandards and the
s tandards i n exi s tence for i nformati on technol ogy
6.5
Incident Impact: Cultural Impact
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto
nuances of vari ous cul tural i nterpretati ons and vi ews toward technol ogy and cyber s ecuri ty
Accuratel y anal yzes the i nfl uence thi s i nci dent may have
had on vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce
Anal yzes the i nfl uence thi s i nci dent may have had on
vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce, but wi th gaps i n accuracy or
detai l
Does not anal yze the i nfl uence thi s i nci dent may have had on
vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce
6.5
Recommendations: Organizational
Changes
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto s ol vi ng organi zati onal i ss ues
Propos es and defends rel evant changes to the organi zation that woul d have hel ped prevent the i nci dent
Propos es and defends changes to the organi zation, but changes are not rel evant or not comprehens i vel y defended, or
woul d not have hel ped prevent the i nci dent
Does not propos e and defend changes to the organi zation
6.5
Recommendations: Ethical Guidelines
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the
nuanced ethi cal s tandard needs of organi zati ons
Propos es reas onabl e ethi cal gui del i nes that coul d have
hel ped prevent the i nci dent and that mi ght hel p prevent future i nci dents wi thi n the organi zati on
Propos es ethi cal gui del i nes , but gui del i nes are not reas onabl e or
woul d not have hel ped prevent the i nci dent or woul d not prevent future i nci dents wi thi n the organi zati on
Does not propos e ethi cal gui del i nes for the organi zati on
6.5
Recommendations:
External Standards
Meets “Profi ci ent” cri teri a and
evi dences keen i ns i ght i nto the nuanced cons i derations requi red when recommendi ng external s tandards for
organi zati ons to fol l ow
Propos es external s tandards
that may have hel ped prevent the i nci dent, wi th rel evant and l ogi cal s upport
Propos es external s tandards
wi th s upport, but the s tandards woul d not have hel ped prevent the i nci dent, or the s upport i s not rel evant or l ogi cal gi ven the
cas e
Does not propos e external
s tandards wi th s upport
6.5
Global Considerations:
International Compliance
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the appl i cati on of i nternati onal s tandards
Accuratel y i denti fi es and expl ai ns i n detai l the i nternati onal compl i ance s tandards rel evant to the
i nci dent
Identi fi es and expl ai ns the i nternati onal compl iance s tandards rel evant to the i nci dent, but wi th gaps i n
accuracy or deta i l
Does not i denti fy and expl ai n the i nternati onal compl iance s tandards rel evant to the i nci dent
6.5
Global
Considerations: Cultural Impacts
Meets “Profi ci ent” cri teri a and
evi dences keen i ns i ght i nto cul tural pers pecti ves toward cyber communi cati on and commerce wi thi n a gl obal
context
Accuratel y anal yzes the i mpact
of the i nci dent on cyber communi cati on and commerce from the l arger cul tural pers pecti ve
Anal yzes the i mpact of the
i nci dent on cyber communi cati on and commerce gl obal l y, but not i n terms of the l arger cul tural pers pecti ve or
wi th gaps i n accuracy
Does not anal yze the i mpact of
the i nci dent on cyber communi cati on and commerce gl obal l y
6.5
Global Considerations:
Global Technology Environment
Meets “Profi ci ent” cri teri a and evi dences a nuanced, i n-depth unders tandi ng of gl obal l egal i mpacts of rel ated cas es
Anal yzes i n detai l the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and
regul ati ons that res ul ted or s houl d have res ul ted
Anal yzes the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and regul ati ons that
res ul ted or s houl d have res ul ted, but wi th gaps i n detai l
Does not anal yze the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and
regul ati ons that res ul ted or s houl d have res ul ted
6.5
Summary
Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto
appropri ate appl icati on of knowl edge to organi zations
Conci s el y s ummari zes and refl ects on how knowl edge of
cyberl aw pri nci ples , ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e
Summari zes and refl ects on how knowl edge of cyberl aw
pri nci pl es, ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e
Does not s ummari ze and refl ect on how knowl edge of cyberl aw
pri nci pl es, ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e
6.5
Articulation of Response
Submi s s i on i s free of errors rel ated to ci tati ons , grammar,
s pel l i ng, s yntax, and organi zati on and i s pres ented i n a profes s i onal and eas y-to-read format
Submi s s i on has no major errors rel ated to ci tati ons , grammar,
s pel l i ng, s yntax, or organi zati on
Submi s s i on has major errors rel ated to ci tati ons , grammar,
s pel l i ng, s yntax, or organi zati on that negati vel y i mpact readabi l ity and arti culation of mai n i deas
Submi s s i on has criti cal errors rel ated to ci tati ons , grammar,
s pel l i ng, s yntax, or organi zati on that prevent unders tandi ng of i deas
2.5
Earned Total 100%