Management Information SystemUnit 49 min read
Ethics, Privacy, Security & Social Impact in IS
Unit 4 of Management Information System explores ethical dilemmas, privacy laws, cybersecurity threats, and the societal impact of information systems, with real-world cases from Nepal and global tech giants.
TAKEAWAYS:
- Ethical dilemmas in IS arise from conflicts between profit, privacy, and public good (e.g., data selling vs. user consent).
- Privacy laws (like Nepal’s Digital Transaction Act) regulate data collection, storage, and sharing—violations risk fines or lawsuits.
- Cybersecurity threats (malware, phishing, ransomware) exploit human error and system vulnerabilities, costing billions annually.
- Social impacts of IS include digital divide, job displacement, and surveillance—requiring ethical AI and inclusive policies.
- Corporate responsibility demands transparency, accountability, and stakeholder engagement (e.g., banks vs. fintech apps).
- Exam focus: Case studies (e.g., Facebook-Cambridge Analytica), legal frameworks, and ethical decision-making frameworks.
1. Ethical Issues in Information Systems
Ethics in IS refers to principles guiding right vs. wrong behavior in designing, using, and managing information systems. Key dilemmas include:
- Profit vs. Privacy: Companies profit from user data (e.g., ads) but must respect consent.
- Access vs. Security: Open data improves services but risks breaches (e.g., hacked databases).
- Transparency vs. Secrecy: Governments/enterprises hide data for security but may abuse power.
Ethical Decision-Making Frameworks
Three models help resolve dilemmas:
Worked Example: eSewa’s Data Sharing
- Scenario: eSewa collects user transaction data. Should it sell anonymized trends to merchants?
- Analysis:
- Utilitarian: Helps merchants target customers → more sales.
- Rights: Users may not consent to data resale (violates Digital Transaction Act).
- Justice: Small merchants benefit, but users bear privacy risks.
- Decision: eSewa should aggregate data without personal identifiers and disclose practices transparently.
2. Privacy and Security in the Digital Age
Privacy: Legal and Ethical Boundaries
Privacy protects personal data from unauthorized access. Key laws:
| Law/Standard | Scope | Nepal Example |
|---|---|---|
| GDPR (EU) | EU citizen data | Applies to Nepali firms processing EU data. |
| Digital Transaction Act (Nepal) | E-commerce, banking data | Bans unauthorized data sharing by fintechs. |
| HIPAA (US) | Health records | Relevant for hospitals using EHR systems. |
How Privacy Works in Systems:
- Data Collection: Only collect necessary data (e.g., Daraz asks for email, not SSN).
- Storage: Encrypt data (e.g., Nabil Bank uses AES-256 for customer records).
- Sharing: Anonymize or get explicit consent (e.g., Khalti’s KYC process).
Security Threats and Countermeasures
Cyber threats exploit human error or system flaws. Common attacks:
classDiagram
class Threat {
+Name: String
+Impact: String
+Prevention: String
}
class Malware {
+Examples: Viruses, Ransomware
+Prevention: Antivirus, Updates
}
class Phishing {
+Examples: Fake emails, Spoofed sites
+Prevention: User training, 2FA
}
class DDoS {
+Examples: Botnets, Traffic floods
+Prevention: Firewalls, Rate limiting
}
Threat <|-- Malware
Threat <|-- Phishing
Threat <|-- DDoSReal-World Example: Ncell’s SIM Hack (2021)
- Threat: Phishing emails tricked users into downloading malware, stealing login credentials.
- Impact: 50,000+ accounts compromised; fraudulent calls billed to victims.
- Solution: Ncell rolled out biometric authentication and SMS alerts for logins.
3. Social Issues and Digital Divide
Information systems create unintended consequences:
- Digital Divide: Urban Nepalese use smartphones, but rural areas lack internet (only 50% coverage).
- Job Displacement: Automation (e.g., Daraz’s warehouse robots) replaces manual labor.
- Surveillance: Facial recognition in Kathmandu traffic cameras raises privacy concerns.
Case Study: Pathao’s Gig Economy
Solution: Pathao could partner with NGOs to offer low-cost internet vouchers for drivers, addressing the digital divide.
4. Ethical AI and Corporate Responsibility
AI systems (e.g., NEPSE’s stock prediction tools) must be fair, transparent, and accountable.
- Bias: Training data may exclude rural investors → skewed recommendations.
- Accountability: Who is liable if an AI loan approval system discriminates? (e.g., Nabil Bank’s AI model rejecting women borrowers.)
- Transparency: Explainable AI (XAI) helps users trust systems (e.g., Google’s "Why was this ad shown?").
Example: Toyota’s Ethical AI Guidelines
- Safety: Self-driving cars must prioritize pedestrian lives over passengers.
- Privacy: Location data from cars is anonymized.
- Transparency: Users can opt out of data collection.
In the Real World
Khalti’s KYC Process
- Idea: Privacy vs. Security
- How: Khalti verifies users via biometric data (fingerprint/face) but stores only hashed versions (not raw images). This balances fraud prevention with privacy.
- Ethical Dilemma: Should Khalti share KYC data with banks without user consent? (Answer: No—violates Digital Transaction Act.)
Daraz’s Order Fulfillment Queue
- Idea: Justice in Resource Allocation
- How: Daraz uses FIFO (First-In-First-Out) queues for orders, but premium users get priority. Critics argue this creates an unfair advantage for wealthy customers.
- Ethical Question: Should Daraz offer discounts to low-income users to level the playing field?
NTC’s Net Neutrality Policy
- Idea: Access vs. Profit
- How: NTC blocks VoIP apps (e.g., WhatsApp calls) to protect revenue from traditional telecom. This restricts user choice.
- Real Impact: Rural schools can’t use free calling apps for distance learning.
Exam Tip
Case Study Analysis (30% weight)
- Format: Describe the scenario → identify ethical/social issues → apply frameworks (utilitarian/rights/justice) → propose solutions.
- Example Question:
"Nepal’s NEPSE stock exchange uses AI to predict trends. A trader accuses the system of favoring institutional investors. Discuss the ethical concerns and how NEPSE can improve fairness."
- Answer Structure:
- Issue: Algorithmic bias → institutional investors get better predictions.
- Framework: Justice (fair access to tools) and Rights (transparency for all users).
- Solution: Audit AI models for bias; publish prediction methodologies.
Short-Answer Questions (20%)
- Define terms precisely:
- "Explain the difference between data privacy and data security." (Privacy = control over data; security = protection from breaches.)
- Compare concepts in tables (e.g., GDPR vs. Digital Transaction Act).
- Define terms precisely:
Scenario-Based Questions (25%)
- Example:
"A hospital in Pokhara uses EHR systems. A patient’s data is leaked due to poor encryption. Who is liable? How could this be prevented?"
- Answer:
- Liable: Hospital (failed to encrypt data per HIPAA-like standards).
- Prevention: Use end-to-end encryption (e.g., like Nabil Bank’s patient portals).
- Example:
True/False (10%)
- "Phishing attacks target system vulnerabilities." (False—targets human error.)
Visuals in Exams
- Expect flowcharts (e.g., ethical decision-making) or tables (e.g., comparing laws). Practice drawing:
- A data privacy lifecycle.
- A cybersecurity threat matrix (axes: likelihood vs. impact).
- Expect flowcharts (e.g., ethical decision-making) or tables (e.g., comparing laws). Practice drawing:
Final Checklist for Full Marks: ✅ Link every point to Nepal’s context (e.g., Digital Transaction Act, Ncell, Daraz). ✅ Use real examples (not hypotheticals) for case studies. ✅ Draw one mermaid diagram (e.g., ethical frameworks) and one table (e.g., laws). ✅ End with a clear solution to dilemmas (e.g., "Khalti should anonymize data").
Based on the TU BIT syllabus for Management Information System (BIT353), unit 4.
Discussion
Loading…