1.1 ACCEPTABLE AND UNACCEPTABLE PROFESSIONAL PRACTICES FOUND IN THE COMPUTER INDUSTRY.
What is Professional Ethics?
Professional Ethics concerns one’s conduct of behaviour and practice when carrying out professional work. Such work may include consulting, researching, teaching and writing. The institutionalisation of Codes of Conduct and Codes of Practice is common with many professional bodies for their members to observe.
Any code may be considered to be a formalisation of experience into a set of rules. A code is adopted by a community because its members accept the adherence to these rules, including the restrictions that apply.
It must be noted that there is a distinction between a profession such as Information Systems, and controlled professions such as Medicine and Law, where the loss of membership may also imply the loss of the right to practice.
Apart from codes of ethics, professional ethics also concerns matters such as professional indemnity. Furthermore, as will readily be appreciated, no two codes of ethics are identical. They vary by cultural group, by profession and by discipline. The former of these three variations is one of the most interesting, as well as controversial, since it challenges the assumption that universal ethical principles exist. In some cultures, certain behaviours are certainly frowned upon, but in other cultures the opposite may be true. Software piracy is a good case in point, in that attitudes towards software piracy vary from strong opposition to strong support – attitudes that are supportable within a particular culture. At the end of these pages is a section called Cultural Perspectives, where we hope to point you to alternative perspectives of ethical standards, attitudes and behaviours..
Software Engineering Code of Ethics and Professional Practice
PREAMBLE
Computers have a central and growing role in commerce, industry, government, medicine, education, entertainment and society at large. Software engineers are those who contribute by direct participation or by teaching, to the analysis, specification, design, development, certification, maintenance and testing of software systems. Because of their roles in developing software systems, software engineers have significant opportunities to do good or cause harm, to enable others to do good or cause harm, or to influence others to do good or cause harm. To ensure, as much as possible, that their efforts will be used for good, software engineers must commit themselves to making software engineering a beneficial and respected profession. In accordance with that commitment, software engineers shall adhere to the following Code of Ethics and Professional Practice.
The Code contains eight Principles related to the behavior of and decisions made by professional software engineers, including practitioners, educators, managers, supervisors and policy makers, as well as trainees and students of the profession. The Principles identify the ethically responsible relationships in which individuals, groups, and organizations participate and the primary obligations within these relationships. The Clauses of each Principle are illustrations of some of the obligations included in these relationships. These obligations are founded in the software engineer’s humanity, in special care owed to people affected by the work of software engineers, and the unique elements of the practice of software engineering. The Code prescribes these as obligations of anyone claiming to be or aspiring to be a software engineer.
It is not intended that the individual parts of the Code be used in isolation to justify errors of omission or commission. The list of Principles and Clauses is not exhaustive. The Clauses should not be read as separating the acceptable from the unacceptable in professional conduct in all practical situations. The Code is not a simple ethical algorithm that generates ethical decisions. In some situations standards may be in tension with each other or with standards from other sources. These situations require the software engineer to use ethical judgment to act in a manner which is most consistent with the spirit of the Code of Ethics and Professional Practice, given the circumstances.
Ethical tensions can best be addressed by thoughtful consideration of fundamental principles, rather than blind reliance on detailed regulations. These Principles should influence software engineers to consider broadly who is affected by their work; to examine if they and their colleagues are treating other human beings with due respect; to consider how the public, if reasonably well informed, would view their decisions; to analyze how the least empowered will be affected by their decisions; and to consider whether their acts would be judged worthy of the ideal professional working as a software engineer. In all these judgments concern for the health, safety and welfare of the public is primary; that is, the “Public Interest” is central to this Code.
The dynamic and demanding context of software engineering requires a code that is adaptable and relevant to new situations as they occur. However, even in this generality, the Code provides support for software engineers and managers of software engineers who need to take positive action in a specific case by documenting the ethical stance of the profession. The Code provides an ethical foundation to which individuals within teams and the team as a whole can appeal. The Code helps to define those actions that are ethically improper to request of a software engineer or teams of software engineers.
The Code is not simply for adjudicating the nature of questionable acts; it also has an important educational function. As this Code expresses the consensus of the profession on ethical issues, it is a means to educate both the public and aspiring professionals about the ethical obligations of all software engineers
1.2 PROFESSIONAL BODIES IN SOUTH AFRICA. A SHORT DESCRIPTION OF EACH NAMED PROFESSIONAL BODY IS PROVIDED
Professionalism
Students should be encouraged to become involved professionally while they are in school and to continue their professional involvement throughout their career. Several societies and professional organizations are concerned with security
The Computer Society of South Africa
The Computer Society of South Africa (CSSA) is a professional association, established to represent and promote the information and communications technology (ICT) professional and ICT professionalism, as well as to elevate ICT capability in South Africa, and specifically:
* To facilitate the exchange of opinions and views on information and communications technology, and to inform and promote knowledge of ICT to members and the public for the development and use of ICT.
* By representing industry practitioners, to inform and lobby government on ICT policy.
* To obtain from members and other sources information relating to ICT, and to disseminate such information among the public and the Society by means of journals, circulars, publications, lectures, seminars, conferences or otherwise.
* To improve the technical and general knowledge and to elevate the professional status of persons engaged in ICT.
* Education and training to elevate the level of ICT capability in southern Africa.
* Professional development and advancement.
* Community development that enhances the standards and levels of ICT for the greater good of the South African people.
* To do all such other lawful things as are incidental or conducive to the attainment of the above purposes.
Computer Society South Africa has members in all of the provinces in South Africa, and the CSSA has regional representation through chapters in the Western Cape, KwaZulu-Natal and Gauteng.
List PROFESSIONAL BODIES IN SOUTH AFRICA.
______________________________________________________________________________________________________________________________________________________________________________________________________
ISACA South Africa
With more than 100 000 constituents in 160 countries, ISACA (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems (IS) assurance and security, enterprise governance and management of IT, and IT-related risk and compliance. Founded in 1969, the non-profit, independent ISACA hosts international conferences, publishes the ISACA Journal, and develops international IS auditing and control standards, which help its constituents ensure trust in, and value from, information systems. It also advances and attests IT skills and knowledge through the globally respected Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC) designations. ISACA continually updates COBIT, which helps IT professionals and enterprise leaders fulfil their IT governance and management responsibilities, particularly in the areas of assurance, security, risk and control, and deliver value to the business. ISACA in South Africa has chapter representation in all of the key cities, including Johannesburg, Pretoria, Cape Town, Durban, East London, Port Elizabeth and Bloemfontein.
|
Activities |
|
v The description identifies acceptable and unacceptable professional practices found in the computer industry. v The description identifies known professional bodies in South Africa. v Short description of each named professional body is provided. |
____________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The description identifies acceptable and unacceptable professional practices found in the computer industry. |
|
|
|
|
· 2. The description identifies known professional bodies in South Africa. |
|
|
|
|
SPECIFIC OUTCOME 2 : Describe the codes of practice for professionalism in the IT industry in South Africa. |
|
ASSESEMENT CRITERIA |
|
v 1. The description identifies the codes of practice for the IT industry in South Africa. v 2. The description provides a brief explanation of the codes of practice identified. |
2.1 CODES OF PRACTICE FOR PROFESSIONALISM IN THE IT INDUSTRY IN SOUTH AFRICA.
COMPUTER SOCIETY OF SOUTH AFRICA (C.S.S.A.) CODE OF CONDUCT
BASIC APPROACH
The Society is ready at all times to give guidance in the application of the Code of Conduct. In cases where resolution of difficulties is not possible informally, the Society will invoke the disciplinary procedures defined in its Articles of Association. These procedures involve initial discussion to establish the background for a formal complaint, the appointment of a Committee of Enquiry and, if the latter find a case to answer, a Disciplinary Committee. The Disciplinary Committee is empowered to exclude from the Society; to suspend from membership for a given period; to reprimand; to admonish or; of course, to dismiss the case.
NOTE: In case of conflict in the interpretation of any provision contained in this document the English version will prevail.
PRINCIPLES
A PROFESSIONAL MEMBER OF THE COMPUTER SOCIETY OF SOUTH AFRICA.
1. Will behave at all times with integrity. A member will not knowingly lay claim to a level of competence not possessed and will at all times exercise competence at least to the level claimed.
- Will act with complete loyalty towards a client when entrusted will confidential information.
3. Will act with impartiality when purporting to give independent advice and must disclose any relevant interests. - Will accept full responsibility for any work undertaken and will construct and deliver that which has been agreed to.
- Will not seek personal advantage to the detriment of the Society and will actively seek to enhance the image of the Society.
- Will not engage in discriminatory practices in professional activities on any basis whatsoever.
NOTES FOR GUIDANCE
The six principles set out on the previous page make up the Computer Society of South Africa (CSSA) Code of Conduct, and each professional member of the Society, as a condition of membership, undertakes to adhere to these principles. The principles are clear, but have an inevitable appearance of generality. In the following pages each principle is supported by a number of notes for guidance which will help in specific interpretation. Members of the Society will readily appreciate that continued evidence of the determination to abide by the Code will ensure the public trust and confidence in computer professionals which is so necessary to the continuing effective use of computers.
Terminology:
The following conventions apply to the reading of this Code:
1. “A member” includes all categories of corporate membership defined in the Society’s Articles of Association.
2. “Client” is any person, or organisation for whom the member works, or undertakes to provide computer-based aid, in any way.
- “User” is any person, department or organisation served by computer-based systems.
4. “System” means all applications involving the use of computer and information technology. The term does not imply any particular mode of processing, eg. local batch or remote real time, etc. “System” may be interpreted as encompassing non-computer procedures and disciplines, eg. Clerical, Manual, etc.
Integrity:
“A member will behave at all times with integrity. A member will not knowingly lay claim to a level of competence not possessed, and will at all times exercise competence at least to the level claimed.”
Integrity implies wholeness, soundness, completeness: anything the member does should be done competently. Where necessary, additional guidance or expertise should be obtained from properly qualified advisers. While claims to competence should not be made lightly, a member will not shelter behind this principle to avoid being helpful and co-operative; any guidance or advice that can be provided from experience should be readily given. A member should act in a manner based on trust and good faith towards clients or employers and towards others with whom he or she is associated. A member should express an opinion on a subject only when it is founded on adequate knowledge and honest conviction, and will properly qualify any opinion expressed outside the level of professional competence attained. A member should not deliberately make false or exaggerated statements as to the state of affairs existing or expected regarding any aspect of the construction or use of computers. A member should comply with the CSSA Code of Practice and any other codes that are applicable and ensure that clients are aware of the significance of his or her work. A member has an obligation to be aware of relevant developments in information technology. A member should not engage in any illegal activities, including copyright or patent violations.
Confidentiality:
“A member will act with complete loyalty towards a client when entrusted with confidential information. A member shall take adequate measures to ensure the confidentiality of a client’s information. A member should not disclose, or permit to be disclosed, or use to personal advantage, any confidential information relating to the affairs of present or previous employers or customers without their prior permission. This principle covers the need to protect confidential data.
Many kinds of information can be considered by a client or employer to be confidential. Even the fact that a project exists may be sensitive. Business plans, trade secrets, personal information are all examples of confidential data. Training is required for all staff on measures to ensure confidentiality, to guard against the possibility of a third party intentionally or inadvertently misusing data and to be watchful for leaks of confidentiality arising from careless use of data or indiscretions.
Impartiality:
“A member will act with impartiality when purporting to give independent advice and will disclose any relevant interests.” This principal is primarily directed to the case where a member or members relatives or friends may make a private profit if the client or employer follows advice given. Any such interest should be disclosed in advance. A second interpretation is where there is no immediate personal profit but the future business or scope of influence of the department depends on a certain solution being accepted. Whereas salesperson are assumed to have a bias towards their own company, an internal consultant should always consider the welfare of the organisation as a whole and not just the increased application of computers.
Responsibility:
“A member will accept full responsibility for any work undertaken and will construct and deliver that which has been agreed to.” Trust and responsibility are at the heart of professionalism. A member should seek out responsibility and discharge it with integrity. A member should complete the work accepted within the agreed time and budget. If that which has been promised cannot be achieved then the client or employer must be alerted at the earliest possible time so that corrective action can be taken. Members should have regard to the effect of computer based systems, insofar as they are known to them, on the basic human rights of individuals, whether within the organisation, its customers or suppliers, or among the general public. Subject to the confidential relationship between themselves and their customers, members are expected to transmit the benefit of information acquired during the practice of the profession, as a result of technical knowledge, to alleviate any situation which may harm or seriously affect a third party. A member should combat ignorance about technology wherever it is found, and in particular in those areas where application of technology appears to have dubious social merit.
Relationship to the Society:
“A member will not seek personal advantage to the detriment of the Society and will actively seek to enhance the image of the Society.” It is necessary to write this principle into the Code of Conduct to prevent misuse of the considerable influence that a professional society can have. Nevertheless, its impact is largely internal and the points that have been made should be read in that light.
A member should not bring the Society into disrepute by personal behaviour or acts when acknowledged or known to be a representative of the Society. A member should not misrepresent the views of the Society nor represent that the views of a segment or group of the Society constitutes the view of the Society as a whole. When acting or speaking on behalf of the Society members should, if faced with conflict of interest, declare their position. Members should not serve their own pecuniary interests or those of the company which normally employs them when purporting to act in an independent manner as representative of the Society, save as permitted by the Society following a full disclosure of all the facts. Members are expected to apply the same high standard of behaviour in their social life as is demanded of them in their professional activities insofar as these interact. Confidence is at the root of the validity of the qualifications of the Society and conduct which in any way undermines that confidence (e.g. a gross breach of a confidential relationship) is of deep concern to the Society. Members should conduct themselves with courtesy and consideration towards all with whom they come into contact in the course of their professional work.
A member should have regard to the great extent that professional and other bodies depend on voluntary effort and should consider what personal contribution can be made both to the public generally and to the Society, in order to enhance the image of the Society and the quality of work delivered by its members. In this regard the member will inter alia seek co-operation with related professional bodies. A member should avoid any behaviour which impinges on the reputation of any other member of the Society.
Non-discrimination:
“A member will not engage in discriminatory practises in professional activities, on any basis whatsoever.” Professional people should ensure that their dealings with others are free from unfair discriminatory behaviour. Wherever they have the opportunity to control or influence the hiring and management of employees, their decisions should be based solely on the skills, experience and performance of the employee. This implies hiring and remunerating on an equal opportunity basis.
Wherever possible, members should support and/or initiate programmes which encourage the development and training of professionals and managers on an equal opportunity basis.
DISCIPLINARY PROCEDURE
All members of the Society undertake to abide by the Society’s Code of Conduct. It will sometimes happen, however, that someone (member or non-member) wishes to lay a complaint against a member for infringement of the Code, and this note explains the Society’s procedures. Professional workers exercise not only the skills which they have learned in formal education and training, but also mature personal judgement developed from the use of those skills, in the varying situations of day-to-day working life. The level of members’ professional objectives will be dependent on, amongst other things, their seniority, their position and their type of work.
Consultants carry additional professional obligations. A senior executive in charge of a major computer application or computer project is responsible for the accuracy of the information produced by the installation and for ensuring that those for whom it is prepared are fully aware of its limitations in relation to the purpose for which they intend to use it; a person cannot, however, be held responsible if it is used for a purpose of which they are unaware or for which it was not intended. The responsibility of senior systems analysts and programmers is also heightened because their work is so little understood by others and failures can have serious consequences. It must, however, be borne in mind that the more responsibility a member carries, the higher will be the standard expected of him or her, and the more rigorously may the Society’s sanctions have to be applied. In the interest of the public, the highest standard will be expected of those in public practice who by nature of their work accept personal responsibility for what they undertake. The Society has no legal standing between a member and his employer, whether an individual or a company. Its remedy lies in giving, where appropriate, fullest support for the stand taken by a member who loses a job, or is in danger of doing so, and of censuring the employer who seeks to place the member in a position which could cause violation of the Society’s Code of Conduct. The Society’s disciplinary regulations clearly set out the procedures to be followed. In essence, however, they provide for the processing of complaints against members, or former members of the Society, in two stages. Firstly: all complaints should be in writing and addressed to the Executive Director of the Society. These complaints may be lodged by any person, organisation or Chapter committee or where Council resolves to proceed against any member or former member for breach of the Code of Conduct. The complaint will then be investigated by a Committee of Enquiry which has the power to summon any member or former member, whom the committee believes may be able to provide information concerning the subject matter of the complaint, to appear before it. Should the Committee of Enquiry believe that a case of misconduct has been established then the member or former member will be given 21 days notice to answer the complaint. If no written representation is received, or if the committee is not satisfied that the complaint has been answered, then the complaint will be referred to the Disciplinary Committee. Should the complaint be found, by the Committee of Enquiry, to be without substance, the complainant will be advised accordingly. Secondly: where the complaint is referred to the Disciplinary Committee a formal hearing of the charge will be arranged. Witnesses may be called but no legal representation will be permitted at the hearing and all proceedings will be held in camera. If found guilty of the charge, the member may be cautioned or reprimanded, suspended from membership for a period or expelled from membership of the Society for life. Where the sentence is a caution and reprimand, the Council shall circularise all members setting out the nature of the circumstances and the result of the hearing but not the name of the member. Where the member has however been suspended or expelled, the Council shall, to the extend it deems expedient, advise all members of the fact and name of the member, for their exclusive and confidential information.
THE CODE AS APPLIED TO A CONSULTANT
Advice given to a client can come from:
(a) Outside an organisation, either for a fee or as part of a supplier’s marketing effort or after-sales support;
(b) Within the organisation from business analysts or system designers working directly or indirectly for a user. Irrespective of conditions of employment, consultants are expected to give sound advice and honest opinions, and to help the client to a successful planned conclusion. The following points amplify the notes for guidance in respect for consultancy work. Members should hold themselves accountable for the advice given to their client’s, and should ensure that all known limitations of their work are fully disclosed, documented and explained.
A member should not attempt to avoid the consequences of poor advice by making the language of any report incomprehensible to the layman by the use of computer jargon.
A member should ensure that the client is aware of all significant contingencies and risks which could adversely affect plans and the scale of the costs which may be incurred as a result of embarking on any particular computer strategy. During the course of the work, the member should bring to the client’s attention, at the earliest possible time, any risk that the stated objectives may not be achievable or any risk attaching to the objective of which the client may not be aware; and if the solution lies in the extension of the contract, best efforts should be used to make the necessary time available at an equitable fee. Where it is possible that decisions may be made as a result of a member’s efforts which could adversely affect the social benefits, work or career of any individual, the member should ensure that the clients are aware of their responsibilities to mitigate the effects of their decisions.
Members should always have regard to any factors arising during a professional assignment which might reflect adversely upon their integrity and objectivity. Members should declare to their client, before accepting instructions, all interests which may affect the proper performance of their functions. For example:
(a) a directorship or controlling interest in any business which is in competition with the client;
(b) a financial interest in any goods or services recommended to the client;
(c) a personal relationship with any person in a client’s employment who might influence, or be directly affected by, advice given. When undertaking consultancy work, a written agreement must be provided which clearly states the basis or amount of remuneration before undertaking the assignment. A member is expected not to structure fees in any way so as to offset impartiality; examples which have in the past been regarded as suspect include fee splitting, and payment by results.
A member should not invite any employee of a client to consider alternative employment without prior consent of that client. (An advertisement in the press is not considered to be an invitation to any particular person for the purpose of this rule.)
THE CODE AS APPLIED TO SALESPERSONS
Almost everyone in computing is from time to time in the position of salesperson – either in direct contact with clients and customers, or with those who, because they are dependent on results from computing, are in the position of clients. Salespeople are normally direct employees of their companies, and it is implicit that whatever they promise to a customer should be delivered by the company. Salespersons must therefore act loyally and honestly as employees and should declare their status as representatives of the company. Payment by results in the form of commission to a salesperson is an accepted business practice; but in the selling of a continuing system it is probably desirable that some or all of such commission be tied to the proper performance of the work and the long term satisfaction of the customer. The member should act in a manner based on trust and good faith towards customers, to ensure that they receive lasting and profitable enjoyment of their purchase. For example :
– members should accept only such work as they believe the organisation can produce and deliver;
– members should ensure that any agreement with the customer is explicit, unambiguous and complete;
– members should obey the spirit as well as the letter of any contract and of the law;
– members should secure after-sales service where appropriate commensurate with the kind of product supplied and the price paid;
– members should ensure that the customer is aware of any contingencies under which supplementary charges may be payable and the basis of such charges;
– members should ensure that customers are aware of any significant risks e.g. imminent obsolescence, replacement or supercession of facilities, which could adversely affect their plans, and of any additional work or expense they will or may incur in using the service or product which is being offered to them;
– with the prior consent of the client, members should sub-contract only to responsible practitioners and organisations;
– members should avoid illegal “informal” price fixing and market sharing arrangements tending to falsify the process of tendering and open competition;
– members should not be party to any practice which could lead to commercial or other corruption;
– members should not use products commissioned and paid for by one client for another client, without the knowledge and agreement of the original client;
– members should not denigrate the honesty or competence of a fellow professional or competitor with intent to gain unfair advantage;
– members should not maliciously or recklessly injure or attempt to injure, directly or indirectly, the professional reputation, prospects or business of others;
– members should not exploit customer relations by using either the existence of any contract or any identifiable precis of work done in any advertising or publicity material without the permission of the client.
|
Activities |
|
v Description identifies the codes of practice for the IT industry in South Africa. v The description provides a brief explanation of the codes of practice identified. |
_______________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The description identifies the codes of practice for the IT industry in South Africa. |
|
|
|
|
· 2. The description provides a brief explanation of the codes of practice identified. |
|
|
|
|
· |
|
|
|
|
SPECIFIC OUTCOME 3: Describe the code of ethics in the computer industry in South Africa. |
|
ASSESEMENT CRITERIA |
|
v 1. The description confirms that the computer industry supports equality of opportunity. v 2. The description confirms the understanding that the computer industry is against computer software piracy. v 3. The description identifies ways in which piracy is addressed in South Africa. |
3.1 CODE OF ETHICS IN THE COMPUTER INDUSTRY IN SOUTH AFRICA
Codes of Ethics are concerned with a range of issues, including:
»Academic honesty
»Adherence to confidentiality agreements
»Data privacy
»Handling of human subjects
»Impartiality in data analysis and professional consulting
»Professional accountability
»Resolution of conflicts of interest
»Software piracy
- Computerworld’s first priority is the interest of its readers.
- Editorial decisions are made free of advertisers’ influence.
- We insist on fair, unbiased presentation in all news and articles.
- No advertising that simulates editorial content will be published.
- Plagiarism is grounds for dismissal.
- Computerworld makes prompt, complete corrections of errors.
- Journalists do not own or trade in computer industry stocks.
- No secondary employment in the IT industry is permitted.
- Our commitment to fairness is our defense against slander.
- All editorial opinions will be clearly labeled as such.
- Ethics
- Ethics and Responsible Decison-Making
The foundation of all security systems is formed by moral principles and practices of those people involved and the standards of the profession. That is, while people are part of the solution, they are also most the problem. Security problems with which an organization may have to deal include: responsible decision making, confidentiality, privacy, piracy, fraud & misuse, liability, copyright, trade secrets, and sabotage. It is easy to sensationalize these topics with real horror stories; it is more difficult to deal with the underlying ethical issues involved.
The student should be made aware of his individual responsibility in making ethical decisions associated with information security.
- Confidentiality & Privacy
Computers can be used symbolically to intimidate, deceive or defraud victims. Attorneys, government agencies and businesses increasingly use mounds of computer generated data quite legally to confound their audiences. Criminals also find useful phony invoices, bills and checks generated by the computer. The computer lends an ideal cloak for carrying out criminal acts by imparting a clean quality to the crime.
The computer has made the invasion of our privacy a great deal easier and potentially more dangerous than before the advent of the computer. A wide range of data are collected and stored in computerized files related to individuals. These files hold banking information, credit information, organizational fund raising, opinion polls, shop at home services, driver license data, arrest records and medical records. The potential threats to privacy include the improper commercial use of computerized data, breaches of confidentiality by releasing confidential data to third parties, and the release of records to governmental agencies for investigative purposes.
Fraud & Misuse
The computer can create a unique environment in which unauthorized activities can occur. Crimes in this category have many traditional names including theft, fraud, embezzlement, extortion, etc. Computer related fraud includes the introduction of fraudulent records into a computer system, theft of money by electronic means, theft of financial instruments, theft of services, and theft of valuable data.
Patents and Copyright Law
A patent can protect the unique and secret aspect of an idea. It is very difficult to obtain a patent compared to a copyright. With computer software, complete disclosure is required; the patent holder must disclose the complete details of a program to allow a skilled programmer to build the program. Moreover, a United States software patent will be unenforceable in most other countries.
Copyright law provides a very significant legal tool for use in protecting computer software, both before a security breach and certainly after a security breach. This type of breach could deal with misappropriation of data, computer programs, documentation, or similar material. For this reason the information security specialist will want to be familiar with basic concepts of to copyright law.
Trade Secrets
A trade secret protects something of value and usefulness. This law protects the unique and secret aspects of ideas, known only to the discoverer or his confidants. Once disclosed the trade secret is lost as such and can only be protected under one of the following laws. The application of trade secret law is very important in the computer field, where even a slight head start in the development of software or hardware can provide a significant competitive advantage.
Sabotage
The computer can be the object of attack in computer crimes such as the unauthorized use of computer facilities, alternation or destruction of information, data file sabotage and vandalism against a computer system. Computers have been shot, stabbed, short-circuited and bombed.
WAYS IN WHICH PIRACY IS ADDRESSED IN SOUTH AFRICA-CASE STUDY
Software Piracy Rife in South Africa
Pirated computer software is currently costing legal resellers and the local computer industry millions of rands a month through lost revenues – and leaving thousands of unsuspecting computer owners up the creek without support.
Microsoft South Africa’s Charl Everton says her company alone is currently busy investigating more than 60 computer dealers suspected of selling fake or illegally licensed software – and that’s “just the tip of the iceberg,” she says.
Overall, the trade in counterfeit goods is costing South Africa millions of rands annually in lost revenues, says Mandla Mnyatheli, chief director of company and IP enforcement with the Department of Trade and Industry (DTI).
“The exact impact of counterfeiting is hard to quantify, but there’s no doubt this trend has been increasing. We have an urgent challenge in South Africa to stem this tide,” said Mnyatheli.
The Deputy Minister of Trade and Industry, Ms Tobias-Pokolo, is spearheading a nationwide campaign to raise awareness of the scourges of piracy and counterfeiting, says Mnyatheli. All relevant enforcement agencies and government departments in the security cluster will be part of this campaign.
The biggest problem with piracy, though, says Ms Everton, is that there is growing evidence that many local criminal organisations are now involved in counterfeiting to some degree – which effectively means that people who buy pirated goods are funding organised crime.
“All indications are that local criminal syndicates are following the global trend of branching out into counterfeit software as a low-risk, high-profit sideline to other activities like hijacking and drug trafficking,” she said.
Ms Everton was speaking as part of Microsoft’s worldwide ‘Consumer Action Day’ – a drive across 70 countries to protect consumers and increase awareness of the risks of counterfeit software.
She says that every year, thousands of consumers and businesses buy counterfeit products that either don’t work or actually harm the users by opening the door to online spam, virus and fraud networks. Microsoft’s tests of software on some popular sites have shown that up to 35 percent of counterfeit software contains harmful code.
Globally, Microsoft has had more than 300 000 voluntary reports in the past two years from people who unknowingly purchased counterfeit software that was often riddled with viruses or malware. Victims risk losing personal information, having their identities stolen, and wasting valuable time and money.
“Consumers everywhere are coming to us with complaints about counterfeit software,” said Dale Waterman, Microsoft’s Corporate Attorney for Anti-Piracy for the Middle East and Africa region. “They’re asking what they can do to protect themselves. They want facts. And they want industry and government to stand up and take action. Our commitment is to do everything we can to help them.”
According to data released by Microsoft this week, based on the results of a broad consumer survey which asked more than 38,000 men and women in 20 countries around the world about their perceptions of counterfeit software, 80 percent of consumers polled worldwide have a range of concerns about the risks of using counterfeit software, and 70 percent said they believe genuine software is more secure, more stable and is easier to keep up-to-date.
But the presence of high-quality fakes in the market today makes distinguishing counterfeit from genuine a continuing challenge for consumers. The majority of those polled — 73 percent — say they would choose genuine software given the choice, and more than two-thirds believe that consumers in general have to be on the lookout or they could mistakenly buy counterfeit software.
As part of its awareness activities, Microsoft this month launched its “Don’t Fake It” campaign, which drives people to the www.dontfakeit.co.za website. There, they get to be part of a music video with popular local band Prime Circle.
There has been no shortage of anti-piracy action by authorities this year. In the past month alone, there have been more than 20 enforcement actions involving the SA Police Services, the DTi or Microsoft’s attorneys against resellers offering pirated software in Bloemfontein and Gauteng. Numerous hard drives used to make counterfeit copies of popular software suites were seized in the raids.
Several of the dealers have been served with ‘cease and desist’ letters by Microsoft’s attorney’s around the sale of counterfeit software and PCs loaded with illegal software.
One of the men netted in the swoop, a prominent Bloemfontein IT consultant, has been charged with offences under the Copyright Goods Act after being caught selling high-quality counterfeit software and product keys on a popular online site.
|
Self-check |
|||
|
|
|||
|
OUTCOME |
Yes |
No |
I Need help |
|
· 1. The description confirms that the computer industry supports equality of opportunity. |
|
|
|
|
· 2. The description confirms the understanding that the computer industry is against computer software piracy. |
|
|
|
|
· 3. The description identifies ways in which piracy is addressed in South Africa. |
|
|
|