CYB_260_Project_One_Brian_Saintsing.docx.

docx

School

Southern New Hampshire University *

*We aren’t endorsed by this school

Course

260

Subject

Business

Date

Feb 20, 2024

Type

docx

Pages

4

Uploaded by HighnessPowerRhinoceros30

Report
CYB 260 Project One Milestone Template I. Analysis of Requirements Select three fair information practice principles from the privacy statement provided by your instructor. Then fill in the blank cells in the table below. Requirements Table Fair Information Practice Principle Applicable Privacy Law or Laws Level of Compliance Safeguards Personal Information Choice HIPPA US Constitution In compliance with state laws Privacy statements should include coverage for children and make sure a parent/guardian has control over what information is shared. Update privacy statements Considerations for minors ALL information and safe and secured at ALL times Consumers can choose to opt in to data collection by organizations 1
Fair Information Practice Principle Applicable Privacy Law or Laws Level of Compliance Safeguards Information collected and how it is used COPPA Fair Credit Reporting Act HIPPA State compliance laws Users are unaware of how their information is safeguarded. The user lacks information regarding the utilization of their data. There is no reference to COPPA or the protection of children's information. E Corp neglects to communicate to users how their data is being gathered. Consumers should receive notification when the company shares their information with an insurance provider. E Corp needs approval from FCRA before sharing information with an insurance provider. The company must inform consumers if it shares their information with an insurance provider. Privacy measures must be updated as necessary. 2
Fair Information Practice Principle Applicable Privacy Law or Laws Level of Compliance Safeguards Access and Correction of Personal Information COPPA FCRA HIPPA State Laws Users can update and change informati on stored by E Corp Users retain the option to update and alter the information held by E Corp. E Corp must enable users to delete the collected information. Encryption is required for both data at rest and data in motion. E Corp should empower parents to control the information collected from their children. II. Business Implications 3
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
A. Discuss the role of ethics as a business driver in this decision. How do the organizational values (as an ethical stance) align to the decision? What responsibility does the organization have pertaining to privacy? Insert your response in the box below. Fit vantage, an E Corp subsidiary, faces a proposal from Helios insurance agency to access data from a new fitness wearable about to launch. Unfortunately, a significant number of potential customers for this wearable express dissatisfaction with the idea. It is Fit-vantage's responsibility to ensure the security of user data collected by their devices. Failure to do so will result in a loss of customer trust and damage Fit-vantage's reputation in the long term. B. Discuss how your personal ethical stance aligns to the decision. How did you apply an ethical framework or decision strategy to inform your position? Insert your response in the box below. In approaching this ethical dilemma, I find myself favoring the utilitarian approach as it reflects my own beliefs in prioritizing harm avoidance and safeguarding user information. I am of the opinion that the Utilitarian framework offers the most beneficial outcome with the least harm for both the company and the consumer. C. What would you recommend the company do? Describe how you came to this decision. How did you balance differences between the organizational ethics and your own personal ethics? Insert your response in the box below. Fit vantage ought to consider the potential of collaborating with Helios. Although this alliance may initially benefit insured patients, it also holds promise for the company by attracting new customers following the launch. Helios must ensure transparency in documenting how they utilize the information to maintain accountability for any malicious or unethical behavior. Given the sensitive nature of the collected data, Helios should consent to an early termination clause as part of the partnership agreement. Customers should receive clear and honest information regarding Helios' handling of consumer data. 4