Computer Security And The Law Essay, Research Paper
Computer Security and the Law
Computer Security and the Law
Table of Contents
Part I Introduction Page 1
Part II The Technological Perspective Page 2
A. The Objectives of Computer Security Page 2
B. Basic Concepts Page 2 4
C. Computer Security Requirements Page 4
Part III The Legal Perspective Page 5
A. Sources of Computer Law Page 5
B. Current Views on Computer Crime Page 5 7
Part IV Conclusion Page 7
References / Works Cited Page 8
Computer Security and the Law
I. Introduction
You are a computer administrator for a large manufacturing company. In the middle of a production run, all of the mainframes on a crucial network grind to a halt. Production is
delayed costing your company hundreds of thousands of dollars. Upon investigating, you find that a virus was released into the network through a specific account. When you confront the owner of the account, he claims he neither wrote nor released the virus, but admits that he has distributed his password to “friends” who need ready access to his data files. Is he liable
for the loss suffered by your company. In whole, or in part. And if in part, for how much. These and related questions are the subject of computer security law. The answers may vary depending on the state in which the crime was committed and the judge who presides at the trial. Computer security law is a new field, and the legal establishment has yet to reach broad agreement on many key issues. Even the meaning of such basic terms as “data” can be
the subject of contention.
Advances in computer security law have been impeded by the reluctance on the part of lawyers and judges to grapple with the technical side of computer security issues [1]. Involving technical computer security professionals in the development of computer security law and public policy could mitigate this problem. This article is meant to help bridge the gap between the technical and legal computer security communities by explaining key technical ideas behind computer security for lawyers and presenting some basic legal background for technical professionals.
II. The Technological Perspective
A. The Objectives of Computer Security
The principal objective of computer security is to protect and assure the confidentiality, integrity, and availability of automated information systems and the data they contain. Each of
these terms has a precise meaning, which is grounded in basic technical ideas about the flow of information in automated information systems.
B. Basic Concepts
There is a broad, top-level consensus regarding the meaning of most technical computer security concepts. This is partly because of government involvement in proposing, coordinating, and publishing the definitions of basic terms [2]. The meanings of the terms used in government directives and regulations are generally made to be consistent with past usage. This is not to
say that there is no disagreement over definitions in the technical community. Rather, the range of such disagreement is much narrower than in the legal community. For example, there is
presently no legal consensus on exactly what constitutes a computer [3].
The term used to establish the scope of computer security is “automated information system,” often abbreviated “AIS.” An AIS is any assembly of electronic equipment, hardware, software, and firmware configured to collect, create, communicate, disseminate, process, store, and control data or information. This includes numerous items beyond the central processing unit and associated random access memory, such as input/output devices (keyboards, printers, etc.)
Every AIS is used by subjects to act upon objects. A subject is any active entity that causes information to flow among passive entities called objects. For example, subject could be a person typing commands, which transfer information from a keyboard (an object) to memory (another object), or a process running on the central processing unit that is sending
information from a file (an object) to a printer (another object).
Confidentiality is roughly equivalent to privacy. If a subject circumvents confidentiality measures designed to prevent its access to an object, the object is said to be “compromised.”
Confidentiality is the most advanced area of computer security because the U.S. Department of Defense has invested heavily for many years to find ways to maintain the confidentiality of
classified data in AIS [4]. This investment has produced the Department of Defense Trusted Computer System Evaluation Criteria [5], alternatively called the Orange Book after the
color of its cover. The Orange Book is perhaps the single most authoritative document about protecting the confidentiality of data in classified AIS.
Integrity measures are meant to protect data from unauthorized modification. Comparing its current state to its original or intended state can assess the integrity of an object. An object, which has been modified by a subject without proper authorization, is said to be “corrupted.” Technology for ensuring integrity has lagged behind that for confidentiality [4].
Наверняка у вас есть товары или услуги, продажа которых приносит вам максимальную прибыль. Для быстрого старта в сети вам необходимо создание посадочной страницы (одностраничного сайта), на которой будет размещена информация о маржинальных товарах/услугах интернет магазина. За 8 лет опыта разработки конверсионных страниц мы выработали оптимальную структуру, которая позволит привлекать через landing page больше продаж. На такую структуру «одевается» ваш контент — фирменный стиль, тексты, фотографии, уникальные торговые предложения, после чего страница выходит в свет. Разработка лендинга и запуск в сети — до 7 рабочих дней. Стоит отметить, что в разработку самой посадочной страницы входит и написание копирайтером продающих текстов для вашего бизнеса, чтобы каждый посетитель страницы захотел совершить покупку именно у вас. Результат: качественно разработаная продающая посадочная страница, которая готова приносить вам новых клиентов.