CYB 260 Project One Milestone Template

docx

School

Southern New Hampshire University *

*We aren’t endorsed by this school

Course

260

Subject

Business

Date

Feb 20, 2024

Type

docx

Pages

2

Uploaded by ISSIT_Learn

Report
CYB 260 Project One Milestone Template I. Analysis of Requirements Select three fair information practice principles from the privacy statement provided by your instructor. Then fill in the blank cells in the table below. Requirements Table Fair Information Practice Principle Applicable Privacy Law or Laws Level of Compliance Safeguards Information Collected and How it is used HIPAA, and individual state laws Specifically states what information is being collected and what it is used for Have the proper security measures to keep PII safe. Control the access to PII. Personal Information and Choice HIPAA and individual state laws This section is vague. It needs to describe what happens when a customer agrees to participate in an activity. State what will happen when a customer decides to participate in activities and what will happen to their data. Use of Cookies The Cookie Law, CCPA, and individual state laws Specifically states what cookies are and how they would be used in the browser. However, there should be something in writing that states that only secure HTTPS connections would be used to connect between systems. Use HTTPS to connect to the web server. It is secure and encrypts the data as it is being exchanged between the system and the server. II. Business Implications A. Discuss the role of ethics as a business driver in this decision. How do the organizational values (as an ethical stance) align to the decision? What responsibility does the organization have pertaining to privacy? Insert your response in the box below. Being ethical is very important in decision making and taking care of customers. In being ethical, we have to be accountable to the organization, it’s employees, and the customers. The organization must ensure that customer PII is safeguarded from unauthorized individuals. The organization must ensure that the data being collected is used according to the set written consent guidelines that the customers has agreed on. The organization must be transparent with its customers when dealing with their sensitive information. The communication should be clear on what is being collected and how it being used. There should also be a discussion on how the data is being stored and what security measures are being taken to safeguard that information. This will protect the company and the customer, and give the customer peace of mind. 1
B. Discuss how your personal ethical stance aligns to the decision. How did you apply an ethical framework or decision strategy to inform your position? Insert your response in the box below. My ethical stance is to think about how the company’s decisions affect everybody involved. If I were in the consumer’s shoes, I want to safeguard my data at all times. If I were to give my sensitive information to someone, I would expect them to comply with my need to safeguard that data. As a stake holder in this company, I must ensure that the organization meets its business needs but also does the right thing when dealing with the consumer, their data, and their needs. This falls under the Utilitarian approach to ethics; thinking about the way actions impact everyone in order to choose the best method that promotes balance for the most stakeholders as possible. C. What would you recommend the company do? Describe how you came to this decision. How did you balance differences between the organizational ethics and your own personal ethics? Insert your response in the box below. I would inform the board of the following. According to the statistics identified in the research; the majority of our customers are not comfortable with sharing any data with our new partners. The company would have to secure the trust of its customers before agreeing to the partnership. On that same note, our Privacy Statement states that we will not use customer information for other that what it is collected for. Is this the same for our new partners? If the answer is yes, then we could use that as a way to inform our current customers and assure them that their data will still be protected and build more trust with them. If not, we would be risking the happiness of our customers and potentially the loss of revenue if they stop using our product. Helios would have to update their Privacy Policy to align with Fit-Vintage’s policy. The customers data must be safeguarded and used in accordance with the guidelines that the customer has agreed upon. 2
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help