Information Technology Incident Report and Summary (Twitter Incident)

profileJBRADDEN
IT659FinalProjectDocument.pdf

IT 659 Final Project Guidelines and Rubric

Overview The final project for this course is the creation of an information technology incident report. Successful management in information technology requires knowledge of the legal and ethical environment. Globalization, increasing commerce between graphical locations brought on by the ability to connect online, and the i ncreasing mix of cultures bring additional complexity to the considerations of law and ethics in cyber security and information technology (IT). The final project for this course will require you to research a recent (within the last five years) incident or event in the field of IT, e-commerce, or cyber security in the context of the legal and ethical standards of that time period. You will identify the issues the organization(s) had, recommend changes for that organization(s), and write a report that highlights your recent analysis, findings, and recommendations. The project is divided into three milestones, which will be submitted at various points throughout the course to scaffold learning and ensure quality final submissions. These milestones will be submitted in Modules Two, Four, and Seven. The final submission will occur in Module Nine. In this assignment you will demonstrate your mastery of the following course outcomes:

 Apply cyberlaw principles appropriately to everyday circumstances, business models, and information technology issues

 Assess legal and compliance issues related to information technology for their impact to organi zations, society, and culture

 Propose relevant changes to organizations and standards that ensure legal and ethical cyber practice and behavior  Determine the impact of various legal cases on compliance and regulatory standards within information technolog y

 Analyze the impact of various cultural attitudes and legal issues related to global communication on information technology

Prompt You will select a recent or current incident from the public record and analyze the case to identify the issues that led to the incident. What recommendations can you make to ensure the incident will not occur again? What were the results of the incident? And, finally, what were the cultural, societal, or global impacts of this case and the subsequent changes to the legal environment? Please note: Your selection will need to be submitted and approved by the instructor. Specifically the following critical elements must be addressed:

I. Introduction a) Apply cyberlaw and security principles to the business, e-commerce, and e-communication industries. What purpose does the application of

cyber principles serve for these industries? b) Summarize the selected case, including the necessary organizational information, industry, problem, and time period of the incident.

II. Case Analysis a) Analyze the case to determine the ethical issues within the organization that may have led to the incident. What are these issues and why do

you credit them for the incident? b) Determine legal compliance issues within the organization that may have led to the incident or could lead to future incidents. Were there any

legal and ethical standards in existence at the time that were not followed by the organization? What were these issues and h ow did they impact the organization?

c) Determine the societal and cultural impact of these compliance issues. Some things to consider in your assessment include specific targeting of demographic groups, victimization of certain customers, and so on.

III. Incident Impact a) Determine the impact this incident may have had on the ethical and legal IT regulations of the time. If there were no direct results of this case,

what may have been the indirect impact and/or what was the impact of similar cases? For example, what regulatory changes resu lted from this or similar cases? What is your reasoning?

b) Determine the connection between the industry standards and the standards in existence for information technology. Specifically, determine if the organization was lacking in either industry-specific or IT-specific alignment with regulations that may have contributed to the incident, and provide support for your conclusions. For example, misalignment with HIPAA laws in healthcare is an industry-specific deviation from standards.

c) Cultural Impact: Analyze the influence this incident may have had on various cultural attitudes toward IT and cyber communication or commerce. In other words, how could this incident impact views of information technology use ?

IV. Recommendations a) Propose relevant changes to the organization that may have prevented the incident. How would these changes have helped to prevent the

occurrence? b) Propose reasonable ethical guidelines that could have helped prevent the incident and that might help the organization prevent future

incidents. c) Propose changes to the standards external to the organization that might have helped prevent the incident. This can include changes to

regulations and regulatory and ethical standards that might exist today but did not exist or were not properly delivered at the time of the incident. Be sure to support your conclusions.

V. Global Considerations a) What international compliance standards (either at the time of the incident or today) would have been relevant to the incident, and how? If

your company is not global, imagine that is. b) Analyze the impact of the incident on global communication and commerce (again, if your organization is not global, imagine otherwise). In

other words, what impact did (or would) the incident have on views and use of information technology and communication in glo bal contexts? c) Global Technology Environment: Based on your research and analysis of this case, determine the global legal and regulatory impacts this case

had on the information technology overall. In other words, determine the relationship between this case and the global regula tory standards that are now in place, will be put in place shortly, or should be put in place as a result of this or related incident(s).

VI. Summary: Given your knowledge of cyberlaw principles, ethical needs, and legal compliance standards, summarize how you applied t hese principles to your analysis of the case. In other words, how did you apply cyberlaw principles to the circumstances, business model, and IT issues that the selected organization faced?

Milestones Milestone One: Introduction In Module Two, you will submit the introduction. In this assignment you will identify the cyberlaw principles and explain how each applie s to the business, e- commerce, or e-communication industries chosen. Describe the purpose of the application of the pri nciples serve for the industry. You will also need to include the necessary organizational information, industry, problem, and the time period of the incident that occurred. The format of this assignment will be a one- to two-page Word document. This milestone is graded with the Milestone One Rubric. Milestone Two: Case Analysis and Incident Impact In Module Four, you will submit the Case Analysis and Incident Impacts. In this assignment you will analyze the ethical issues and determine the legal compliance issues within the organization as well as the social and cultural impacts of these compliance issues. You will be expected to address the impact the incident may have had on the ethical and legal IT regulations at the time. The connection between the industry standards and the standards for informational technology should be determined, as well as the influence of the cultural impact to IT and cyber communication or commerce. The format of this assignment will be a three- to five-page Word document. This milestone is graded with the Milestone Two Rubric. Milestone Three: Recommendations and Global Considerations In Module Seven, you will submit the Recommendations and Global Considerations. In this assignment you will suggest relevant changes to the organi zation itself and changes to the ethical guidelines that could have prevented the incident. Standards external to the organization t hat may have helped prevent the incident should also be proposed. This assignment will also address international compliance standards and how they would have been relevant to the incident. The impact of the incident on global communication and commerce will be analyzed , as well as the impact on the global technology environment. The format of this assignment will be a three- to five-page Word document. This milestone is graded with the Milestone Three Rubric. Final Submission: Information Technology Incident Report and Summary In Module Nine, you will submit your Information Technology Incident Report along with a summary explaining how you applied the principles to your analysis of the case. It should be a complete, polished artifact containing all of the critical elements of the final product. It should reflect the incorporation of feedback gained throughout the course. This submission will be graded using the Final Product Rubric.

Deliverables

Milestone Deliverable Module Due Grading

1 Introduction Two Graded separately; Milestone One Rubric

2 Case Analysis and Incident Impact Four Graded separately; Milestone Two Rubric

3 Recommendations and Global Considerations

Seven Graded separately; Milestone Three Rubric

Final Submission: Information Technology Incident Report and Summary

Nine Graded separately; Final Product Rubric

Final Product Rubric Guidelines for Submission: Your report should be long enough to contain all relevant information, reasoning, and research. It should be formatted logica lly and written in a professional manner, following APA guidelines.

Critical Elements Exemplary (100%) Proficient (90%) Needs Improvement (70%) Not Evident (0%) Value

Introduction: Application of Cyber

Principles

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the

nuanced purpos e of cyber pri nci pl es i n mul ti pl e i ndus tries

Accuratel y appl i es cyber pri nci pl es to the bus i nes s , e-

commerce, and e- communi cati on i ndus tri es to expl ai n the purpos e s erved by

the pri nci pl es

Appl i es cyber pri nci ples to bus i nes s , e-commerce, and e-

communi cati on but wi th gaps i n accuracy or wi thout detai l regardi ng the purpos e s erved

by thes e pri nci ples

Does not appl y cyber pri nci pl es to bus i nes s , e-commerce, and

e-communi cati on

6.5

Introduction: Summary of Case

Meets “Profi ci ent” cri teri a , and qual i ty of i ntroducti ons es tabl i s hes experti s e i n the di s ci pline

Comprehens i vel y and conci s el y i ntroduces the s el ected i nci dent wi th neces s ary organi zational i nformati on, the i ndus try type,

the probl em, and the ti me peri od of occurrence

Introduces the s el ected i nci dent wi th organi zati onal i nformation, the i ndus try type, the probl em, and the ti me peri od of

occurrence, but l acks neces s ary detai l or i ncl udes s uperfl uous i nformati on

Does not i ntroduce the s el ected i nci dent wi th organi zati onal i nformati on, the i ndus try type, the probl em, and the ti me

peri od of occurrence

6.5

Case Analysis: Ethical Issues

Meets “Profi ci ent” cri teri a , and reas oni ng evi dences s trong

ethi cal cri teri a or keen anal yti c s ki l ls regarding organizati onal ethi cs

Accuratel y anal yzes the cas e to determi ne whi ch ethi cal i s sues

wi thi n the organi zati on l ed to the i nci dent, and why

Anal yzes the cas e to determi ne whi ch ethi cal i s s ues wi thi n the

organi zati on l ed to the i nci dent, and why, but wi th gaps i n accuracy or detai l

Does not anal yze the cas e to determi ne whi ch ethi cal i s sues

wi thi n the organi zati on l ed to the i nci dent, and why

6.5

Case Analysis: Legal Compliance

Meets “Profi ci ent” cri teri a and evi dences keen unders tandi ng

of l egal cri teri a of the ti me

Accuratel y determi nes the l egal compl i ance i s s ues wi thi n the

organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues

Determi nes the l egal compl i ance i s s ues wi thi n the

organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues , but wi th gaps i n accuracy or detai l

Does not determi ne the l egal compl i ance i s s ues wi thi n the

organi zati on that l ed to thi s i nci dent and coul d have res ul ted i n other i s s ues

6.5

Case Analysis:

Societal and Cultural Impact

Meets “Profi ci ent” cri teri a and

evi dences deep i ns i ght i nto unexpected, hi dden, or compl ex i mpacts on cul ture and s oci ety

Comprehens i vel y and

accuratel y determi nes the s oci etal and cul tural i mpacts of the l egal and ethi cal compl i ance i s s ues

Determi nes the s oci etal and

cul tural i mpacts of the l egal and ethi cal compl i ance i s sues , but wi th gaps i n accuracy or detai l

Does not determi ne the s oci etal

and cul tural i mpacts of the l egal and ethi cal compl i ance i s sues

6.5

Incident Impact:

Regulations

Meets “Profi ci ent” cri teri a and

evi dences keen unders tandi ng of ethi cal and l egal regul ati ons fol l owi ng the i nci dent

Accuratel y determi nes the

di rect or i ndi rect i mpact of thi s or s i mi l ar case on ethi cal and l egal IT regul ati ons at the ti me

Determi nes the di rect or

i ndi rect i mpact of thi s or s i mi l ar cas e on ethi cal and l egal IT regul ati ons at the ti me, but wi th gaps i n accuracy or l ogi cal

reas oni ng

Does not determi ne the di rect

or i ndi rect i mpact of thi s or s i mi l ar case on ethi cal and l egal IT regul ati ons at the ti me

6.5

Incident Impact: Standards

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto unders tandi ng and appl yi ng IT

and i ndus try-s peci fi c s tandards for i nformati on s ecuri ty

Accuratel y determi nes the connecti on between i ndus try s tandards and s tandards i n

exi s tence for i nformati on technol ogy wi th l ogi cal reas oni ng and s upport

Determi nes the connecti on between the i ndus try s tandards and the s tandards i n exi s tence

for i nformati on technol ogy, but wi th gaps i n accuracy or gaps i n reas oni ng and s upport

Does not determi ne the connecti on between the i ndus try s tandards and the

s tandards i n exi s tence for i nformati on technol ogy

6.5

Incident Impact: Cultural Impact

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto

nuances of vari ous cul tural i nterpretati ons and vi ews toward technol ogy and cyber s ecuri ty

Accuratel y anal yzes the i nfl uence thi s i nci dent may have

had on vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce

Anal yzes the i nfl uence thi s i nci dent may have had on

vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce, but wi th gaps i n accuracy or

detai l

Does not anal yze the i nfl uence thi s i nci dent may have had on

vari ous cul tural atti tudes toward IT and cyber communi cati on or commerce

6.5

Recommendations: Organizational

Changes

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto s ol vi ng organi zati onal i ss ues

Propos es and defends rel evant changes to the organi zation that woul d have hel ped prevent the i nci dent

Propos es and defends changes to the organi zation, but changes are not rel evant or not comprehens i vel y defended, or

woul d not have hel ped prevent the i nci dent

Does not propos e and defend changes to the organi zation

6.5

Recommendations: Ethical Guidelines

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the

nuanced ethi cal s tandard needs of organi zati ons

Propos es reas onabl e ethi cal gui del i nes that coul d have

hel ped prevent the i nci dent and that mi ght hel p prevent future i nci dents wi thi n the organi zati on

Propos es ethi cal gui del i nes , but gui del i nes are not reas onabl e or

woul d not have hel ped prevent the i nci dent or woul d not prevent future i nci dents wi thi n the organi zati on

Does not propos e ethi cal gui del i nes for the organi zati on

6.5

Recommendations:

External Standards

Meets “Profi ci ent” cri teri a and

evi dences keen i ns i ght i nto the nuanced cons i derations requi red when recommendi ng external s tandards for

organi zati ons to fol l ow

Propos es external s tandards

that may have hel ped prevent the i nci dent, wi th rel evant and l ogi cal s upport

Propos es external s tandards

wi th s upport, but the s tandards woul d not have hel ped prevent the i nci dent, or the s upport i s not rel evant or l ogi cal gi ven the

cas e

Does not propos e external

s tandards wi th s upport

6.5

Global Considerations:

International Compliance

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto the appl i cati on of i nternati onal s tandards

Accuratel y i denti fi es and expl ai ns i n detai l the i nternati onal compl i ance s tandards rel evant to the

i nci dent

Identi fi es and expl ai ns the i nternati onal compl iance s tandards rel evant to the i nci dent, but wi th gaps i n

accuracy or deta i l

Does not i denti fy and expl ai n the i nternati onal compl iance s tandards rel evant to the i nci dent

6.5

Global

Considerations: Cultural Impacts

Meets “Profi ci ent” cri teri a and

evi dences keen i ns i ght i nto cul tural pers pecti ves toward cyber communi cati on and commerce wi thi n a gl obal

context

Accuratel y anal yzes the i mpact

of the i nci dent on cyber communi cati on and commerce from the l arger cul tural pers pecti ve

Anal yzes the i mpact of the

i nci dent on cyber communi cati on and commerce gl obal l y, but not i n terms of the l arger cul tural pers pecti ve or

wi th gaps i n accuracy

Does not anal yze the i mpact of

the i nci dent on cyber communi cati on and commerce gl obal l y

6.5

Global Considerations:

Global Technology Environment

Meets “Profi ci ent” cri teri a and evi dences a nuanced, i n-depth unders tandi ng of gl obal l egal i mpacts of rel ated cas es

Anal yzes i n detai l the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and

regul ati ons that res ul ted or s houl d have res ul ted

Anal yzes the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and regul ati ons that

res ul ted or s houl d have res ul ted, but wi th gaps i n detai l

Does not anal yze the gl obal l egal and regul atory i mpact of thi s or s i mi l ar cases to determi ne gl obal l aws and

regul ati ons that res ul ted or s houl d have res ul ted

6.5

Summary

Meets “Profi ci ent” cri teri a and evi dences keen i ns i ght i nto

appropri ate appl icati on of knowl edge to organi zations

Conci s el y s ummari zes and refl ects on how knowl edge of

cyberl aw pri nci ples , ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e

Summari zes and refl ects on how knowl edge of cyberl aw

pri nci pl es, ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e

Does not s ummari ze and refl ect on how knowl edge of cyberl aw

pri nci pl es, ethi cal needs , and l egal compl i ance s tandards were appl i ed to the s el ected cas e

6.5

Articulation of Response

Submi s s i on i s free of errors rel ated to ci tati ons , grammar,

s pel l i ng, s yntax, and organi zati on and i s pres ented i n a profes s i onal and eas y-to-read format

Submi s s i on has no major errors rel ated to ci tati ons , grammar,

s pel l i ng, s yntax, or organi zati on

Submi s s i on has major errors rel ated to ci tati ons , grammar,

s pel l i ng, s yntax, or organi zati on that negati vel y i mpact readabi l ity and arti culation of mai n i deas

Submi s s i on has criti cal errors rel ated to ci tati ons , grammar,

s pel l i ng, s yntax, or organi zati on that prevent unders tandi ng of i deas

2.5

Earned Total 100%