Skip the navigation

Dark secrets and ugly truths: When ethics and IT collide

With IT's unfettered access to both professional and personal data, should "follow your conscience" be part of the job description?

By Tam Harbert
September 12, 2007 12:00 PM ET

Computerworld - It still weighs heavily on Bryan's mind, what he found on that executive's computer, especially when he thinks of his own daughters. He's particularly troubled that the man he discovered using a company computer to view pornography of Asian women and of children was subsequently promoted and moved to China to run a manufacturing plant.

"To this day, I regret not taking that stuff to the FBI," says Bryan.

It happened six years ago, when Bryan, who asked that his last name not be published, was IT director for the U.S. division of a $500 million multinational corporation based in Germany.

The company's Internet usage policy, which Bryan helped develop with input from senior management, specifically prohibited the use of company computers to access pornographic or adult-content Web sites. One of Bryan's duties was to monitor employee Web surfing using SurfControl and report any violations to management.

Bryan knew that the executive, who was a level above him in another department, was popular both within the U.S. division and the German parent. So when SurfControl turned up dozens of pornographic Web sites visited by the exec's computer, Bryan figured "my best course of action was to follow the policy."

"That's what it's there for," he reasoned. "I wasn't going to get into trouble for following the policy." He went to his manager with copies of the Web logs in question (which he still has in his possession and made available to Computerworld for verification).

Power and prowess

Bryan's case may be extreme, but it's a good example of the ethical dilemmas that IT workers encounter on the job. IT employees have privileged access to digital information, both personal and professional, throughout the company, and they have the technical prowess to manipulate that information.

That gives them both power and responsibility -- to monitor and report employees who break company rules; to sneak a look at salary information or read personal e-mails that reveal love affairs; or to uncover evidence that a co-worker is embezzling funds from the company.

But ethics professionals, technology industry watchers and IT workers say, there's no consensus on how to wield that power or fulfill that responsibility, at least not officially. And that often puts IT people in uncomfortable positions.

 
Related Story:
Ready to blow the whistle on a cybercrime? Who ya gonna call?


 

In Bryan's case, he didn't get into trouble, but neither did the porn-viewing executive, who beat Bryan to the human resources director with "a pretty outlandish explanation," says Bryan. The executive claimed that his ex-wife was publishing pictures of their kids on the Internet, and he had been trying to find out where. "He said he thought this might show up in a report on him, and he just wanted them to know that he was not going to be doing that anymore."

The company accepted the explanation and tabled the incident, despite Bryan's documentation, which he showed to his direct superior and to human resources and which he insisted be placed into the man's personnel file. Bryan considered going to the FBI, but the Internet bubble had just burst and jobs were hard to come by. "It was a tough choice," he says. "[But] I had a family to feed."

In theory, ethical behavior is governed by federal and state laws, corporate policy, professional ethics and personal judgment. But as Bryan now realizes, and other tech workers discover all the time, navigating those muddy waters can be one of the most daunting challenges in an IT professional's career.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Careers White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Careers White Papers
Careers Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Careers Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs