1 / 4100%
Running Head: IT 659 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
IT-659-Q1436 Cyberlaw and Ethics
SNHU
IT 659 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Introduction
The cyber law has been introduced to keep a tab on the dangerous crimes that
take place in the cyberspace. It is an important element of the Information Technology
whose importance has increased multifold to have a better control over the misuse of
technology. In the 21st century, the popularity of technology-based elements like
computers, smartphone, tablets and the internet has increased. It has further intensified
the need to have a robust cyberlaw system to strengthen various activities that are
carried out in the cyberspace relating to business, e-commerce and e-communication
(Kamble, 2013, p 1).
The cybercrime is any kind of criminal activity that is carried out in the cyber
world. It is basically an unlawful act that is carried out with the intention to use any
computer as the tool to target a specific set of the cyber users. In order to have a tight
control over the rising cybercrimes, the cyber law includes numerous principles to
safeguard the online users (Leocybersecurity.com, 2018). The core principle include the
need to conduct a thorough risk assessment, implementing a robust information security
program, involving the Board of Directors in the Cyber Security Management model,
designating a competent individual who will be in charge of the cybersecurity,
maintaining a methodical incident response program, managing the cybersecurity of the
third-party vendors, conducting the routine security training and regularly updating the
program. These principles have been designed so that online activities of the users can
be safeguarded and they can conduct the same in a safe online environment.
A thorough risk assessment is needed for an e-commerce industry so that the
vulnerabilities can be identified. Based on the identification of the assets of the online
business, the information security program needs to be implemented so that the model
can help the business to mitigate the risks. The management team including the board
IT 659 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
must be included in the cyber security management process so that they can make sound
decisions and play a role to strengthen the cybersecurity model. The Chief Information
System Officer who must be designated to oversee the security model must have
expertise and experience so that the e-commerce activity can be conducted in a safe
setting. A systematic incident response program must be in place which can help the
business to bring about necessary changes in the security plans. Since in the e-commerce
activity, third-party vendors are involved, it is necessary to integrate them in the cyber
security model. Ultimately, online businesses must conduct routine security training and
regularly updating the program so that the vulnerability of the business can be kept
under check (Leocybersecurity.com, 2018).
Maersk, the shipping company was the target of one of the nastiest cyberattacks
that cost it millions of dollars. The ‘Notpetya’ ransomware took advantage of certain
security vulnerabilities of the business and prevented individuals from viewing their data
unless they paid $ 300 in bitcoin (Novet, 2018). Maersk’s operational activities were
affected and it was reported that it lost around $ 300 million. This case indicates that
the shipping industry is unprotected from potential cyberattacks (Ship-technology.com,
2018). The attack took place on June 17th and within a few days crippled its container
shipping, oil tanker operations and entire computer network (Scmagazineuk.com, 2018).
References
Kamble, R. (2013). Cyber Law And Information Technology. Journal Of Scientific &
Engineering Research, 4(5).
Leocybersecurity.com (2018). The 8 Principles of Cyber Security Laws - LEO Cyber
Security. Retrieved from https://leocybersecurity.com/the-8-principles-of-cyber-
security-laws/
IT 659 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
Novet, J. (2018). Shipping company Maersk says June cyberattack could cost it up to
$300 million. Retrieved from https://www.cnbc.com/2017/08/16/maersk-says-
notpetya-cyberattack-could-cost-300-million.html
Ship-technology.com (2018). Did the Maersk cyber attack reveal an industry dangerously
unprepared? - Ship Technology. Retrieved from https://www.ship-
technology.com/features/maersk-cyber-attack-reveal-industry-dangerously-unprepared/
Scmagazineuk.com (2018). NotPetya attack totally destroyed Maersk's computer network:
chairman.. Retrieved from https://www.scmagazineuk.com/notpetya-attack-totally-
destroyed-maersks-computer-network-chairman/article/1473392
Students also viewed