Abstract: Information security professionals develop, communicate and enforce security policy in organizations. Ethical decision-making plays a role in each of these tasks, as it does in any endeavor that pits behavior rules against actual behavior. Policy developers should make an effort to ensure that policies strike a balance between protection of the organization and the rights of employees. Managers in charge of policy dissemination and enforcement should be encouraged to act in ways that maintain ethical interaction between the organization and the employee. Finally, the organization should be willing to re-evaluate policies that fail to treat employees ethically. From development through implementation and review, ethics should influence every decision made in the lifecycle of information security policy. Introduction
For full reading visit
http://www.cpsr.org/act/contest/4wi2