BIT353 Management Information System

Management Information SystemUnit 49 min read

Ethics, Privacy, Security & Social Impact in IS

Unit 4 of Management Information System explores ethical dilemmas, privacy laws, cybersecurity threats, and the societal impact of information systems, with real-world cases from Nepal and global tech giants.

TAKEAWAYS:

  • Ethical dilemmas in IS arise from conflicts between profit, privacy, and public good (e.g., data selling vs. user consent).
  • Privacy laws (like Nepal’s Digital Transaction Act) regulate data collection, storage, and sharing—violations risk fines or lawsuits.
  • Cybersecurity threats (malware, phishing, ransomware) exploit human error and system vulnerabilities, costing billions annually.
  • Social impacts of IS include digital divide, job displacement, and surveillance—requiring ethical AI and inclusive policies.
  • Corporate responsibility demands transparency, accountability, and stakeholder engagement (e.g., banks vs. fintech apps).
  • Exam focus: Case studies (e.g., Facebook-Cambridge Analytica), legal frameworks, and ethical decision-making frameworks.

1. Ethical Issues in Information Systems

Ethics in IS refers to principles guiding right vs. wrong behavior in designing, using, and managing information systems. Key dilemmas include:

  • Profit vs. Privacy: Companies profit from user data (e.g., ads) but must respect consent.
  • Access vs. Security: Open data improves services but risks breaches (e.g., hacked databases).
  • Transparency vs. Secrecy: Governments/enterprises hide data for security but may abuse power.

Ethical Decision-Making Frameworks

Three models help resolve dilemmas:

Maximize overall good (cost-benefit analysis)Example: Should a hospital share patient data to save lives?UtilitarianRespect individual rights (e.g., GDPR)Example: Can a bank sell customer data to insurers?Rights-BasedFair distribution of benefits/burdensExample: Should AI hiring tools favor experienced candidatesJustice-BasedEthical Decision-Making Frameworks
Hierarchical comparison of ethical frameworks with real-world examples

Worked Example: eSewa’s Data Sharing

  • Scenario: eSewa collects user transaction data. Should it sell anonymized trends to merchants?
  • Analysis:
    • Utilitarian: Helps merchants target customers → more sales.
    • Rights: Users may not consent to data resale (violates Digital Transaction Act).
    • Justice: Small merchants benefit, but users bear privacy risks.
  • Decision: eSewa should aggregate data without personal identifiers and disclose practices transparently.


2. Privacy and Security in the Digital Age

Privacy protects personal data from unauthorized access. Key laws:

Law/Standard Scope Nepal Example
GDPR (EU) EU citizen data Applies to Nepali firms processing EU data.
Digital Transaction Act (Nepal) E-commerce, banking data Bans unauthorized data sharing by fintechs.
HIPAA (US) Health records Relevant for hospitals using EHR systems.

How Privacy Works in Systems:

  1. Data Collection: Only collect necessary data (e.g., Daraz asks for email, not SSN).
  2. Storage: Encrypt data (e.g., Nabil Bank uses AES-256 for customer records).
  3. Sharing: Anonymize or get explicit consent (e.g., Khalti’s KYC process).

Security Threats and Countermeasures

Cyber threats exploit human error or system flaws. Common attacks:

classDiagram
    class Threat {
        +Name: String
        +Impact: String
        +Prevention: String
    }
    class Malware {
        +Examples: Viruses, Ransomware
        +Prevention: Antivirus, Updates
    }
    class Phishing {
        +Examples: Fake emails, Spoofed sites
        +Prevention: User training, 2FA
    }
    class DDoS {
        +Examples: Botnets, Traffic floods
        +Prevention: Firewalls, Rate limiting
    }
    Threat <|-- Malware
    Threat <|-- Phishing
    Threat <|-- DDoS
2010Rise of phishingattacks via email2015WannaCryransomware outbreak2020Increase in DDoSattacks during COVID-12023AI-powered cyberthreats emerge
Evolution of major cyber threats over time with key incidents

Real-World Example: Ncell’s SIM Hack (2021)

  • Threat: Phishing emails tricked users into downloading malware, stealing login credentials.
  • Impact: 50,000+ accounts compromised; fraudulent calls billed to victims.
  • Solution: Ncell rolled out biometric authentication and SMS alerts for logins.


3. Social Issues and Digital Divide

Information systems create unintended consequences:

  • Digital Divide: Urban Nepalese use smartphones, but rural areas lack internet (only 50% coverage).
  • Job Displacement: Automation (e.g., Daraz’s warehouse robots) replaces manual labor.
  • Surveillance: Facial recognition in Kathmandu traffic cameras raises privacy concerns.

Case Study: Pathao’s Gig Economy

Job creation for drivers (flexible income)Reduces traffic congestion (ridesharing)Positive ImpactsDrivers lack benefits (no health insurance)Algorithmic bias in fare pricing?Negative ImpactsShould Pathao subsidize fares in remote areas?Ethical DilemmaPathao’s Gig Economy: Social Impact Analysis
Structured analysis of Pathao’s social impact with ethical considerations

Solution: Pathao could partner with NGOs to offer low-cost internet vouchers for drivers, addressing the digital divide.



4. Ethical AI and Corporate Responsibility

AI systems (e.g., NEPSE’s stock prediction tools) must be fair, transparent, and accountable.

  • Bias: Training data may exclude rural investors → skewed recommendations.
  • Accountability: Who is liable if an AI loan approval system discriminates? (e.g., Nabil Bank’s AI model rejecting women borrowers.)
  • Transparency: Explainable AI (XAI) helps users trust systems (e.g., Google’s "Why was this ad shown?").

Example: Toyota’s Ethical AI Guidelines

  1. Safety: Self-driving cars must prioritize pedestrian lives over passengers.
  2. Privacy: Location data from cars is anonymized.
  3. Transparency: Users can opt out of data collection.


In the Real World

  1. Khalti’s KYC Process

    • Idea: Privacy vs. Security
    • How: Khalti verifies users via biometric data (fingerprint/face) but stores only hashed versions (not raw images). This balances fraud prevention with privacy.
    • Ethical Dilemma: Should Khalti share KYC data with banks without user consent? (Answer: No—violates Digital Transaction Act.)
  2. Daraz’s Order Fulfillment Queue

    • Idea: Justice in Resource Allocation
    • How: Daraz uses FIFO (First-In-First-Out) queues for orders, but premium users get priority. Critics argue this creates an unfair advantage for wealthy customers.
    • Ethical Question: Should Daraz offer discounts to low-income users to level the playing field?
  3. NTC’s Net Neutrality Policy

    • Idea: Access vs. Profit
    • How: NTC blocks VoIP apps (e.g., WhatsApp calls) to protect revenue from traditional telecom. This restricts user choice.
    • Real Impact: Rural schools can’t use free calling apps for distance learning.

Exam Tip

  1. Case Study Analysis (30% weight)

    • Format: Describe the scenario → identify ethical/social issues → apply frameworks (utilitarian/rights/justice) → propose solutions.
    • Example Question:

      "Nepal’s NEPSE stock exchange uses AI to predict trends. A trader accuses the system of favoring institutional investors. Discuss the ethical concerns and how NEPSE can improve fairness."

    • Answer Structure:
      • Issue: Algorithmic bias → institutional investors get better predictions.
      • Framework: Justice (fair access to tools) and Rights (transparency for all users).
      • Solution: Audit AI models for bias; publish prediction methodologies.
  2. Short-Answer Questions (20%)

    • Define terms precisely:
      • "Explain the difference between data privacy and data security." (Privacy = control over data; security = protection from breaches.)
    • Compare concepts in tables (e.g., GDPR vs. Digital Transaction Act).
  3. Scenario-Based Questions (25%)

    • Example:

      "A hospital in Pokhara uses EHR systems. A patient’s data is leaked due to poor encryption. Who is liable? How could this be prevented?"

    • Answer:
      • Liable: Hospital (failed to encrypt data per HIPAA-like standards).
      • Prevention: Use end-to-end encryption (e.g., like Nabil Bank’s patient portals).
  4. True/False (10%)

    • "Phishing attacks target system vulnerabilities." (False—targets human error.)
  5. Visuals in Exams

    • Expect flowcharts (e.g., ethical decision-making) or tables (e.g., comparing laws). Practice drawing:
      • A data privacy lifecycle.
      • A cybersecurity threat matrix (axes: likelihood vs. impact).

Final Checklist for Full Marks: ✅ Link every point to Nepal’s context (e.g., Digital Transaction Act, Ncell, Daraz). ✅ Use real examples (not hypotheticals) for case studies. ✅ Draw one mermaid diagram (e.g., ethical frameworks) and one table (e.g., laws). ✅ End with a clear solution to dilemmas (e.g., "Khalti should anonymize data").

Based on the TU BIT syllabus for Management Information System (BIT353), unit 4.

Discussion

Loading…