Working at the gym in the past, I have witnessed employees utilize fake
credit card numbers or even reuse other members' card information in
order to receive more commission. The more accounts and EFTs
(electronic funds transfer) are cleared, the more commission an employee
would make. Ethical morals definitely come into place within any
environment. In this case, there is so much sensitive data available about
customers' names, addresses, credit card numbers, etc. It all depends on
the ethicality of that employee and trust within the company, especially
with the vast data available if seasonal employees would be the right fit.
There are so many requirements now such as having a secret clearance
as well when dealing with the government.
Analysis
1. Do you agree or disagree with the author's assertions
regarding seasonal employees and cybersecurity risks in the
workplace? Why?
A lack of commitment can be shown with seasonal employees regardless
of the project. Although the article mentions, “don’t change the
interview, vetting process or background check requirements” regardless
of the employment type, some seasonal staff may skip this extensive
process. This can lead to not upholding certain morals. Since a seasonal
employee may not be with the company that long, certain morals such
as not caring or not showing “diligence in the performance of duties
under the duty of care” (Reynolds, 2010). The obligation of being
conscientious in performing your duties is due diligence.
2. What steps can (should) managers take to reduce security
risks associated with hiring seasonal or temporary employees?
(Consider whether or not the Secure Computer User training
course would be appropriate for these employees.)
I agree that implementing a solid onboarding process, which is as
extensive as a full-time employee, would be beneficial by holding those
employees accountable. c Using a test environment to see how employees
act around certain data without jeopardizing real company data can also
reduce security risks.
Enforcing acceptable use policies or secure computer user training is
helpful in relation to HOW TO work with the sensitive information or
data, but not the consequences of what will happen with the mishandling
of said data. Especially of those with authorized permission.
The manager could also put seasonal employees on different projects
unrelated to data needs if they feel it will be compromised or
jeopardized.
3. How can managers show leadership in the area of
cybersecurity defenses and best practices?
Integrating security in order to protect corporate assets.
Authorization/authentication methods. Confidentiality agreements, which
is the duty to respect the privacy of information and action
(UMGC,n.d.). As an employee, it is their duty to ensure sensitive data
or information is not shared with just anybody or misused.
Managers should also implement workplace security training and engage
IT professionals for the employees to understand not to overstep the
nature or boundaries of their jobs for “bad”.
References:
Reynolds, G. W. (2010). Ethics in information technology (3rd ed.).
Boston, MA: Course Technology.
University of Maryland Global Campus. (2020). CSIA 300: Why do
businesses need security? Adelphi, MD: Author.
less