---
description: Information systems have made many businesses successful today. Some companies such as Google, Facebook, EBay, etc. would not exist without information technology. However, improper use of information
title: Ethical &#038; Security Issues in Information System
image: https://www.guru99.com/images/ethical-and-security-issues-in-mis.png
---

 

[Skip to content](#main) 

**⚡ Smart Summary**

Ethical and Security Issues in Information System examines how improper use of information technology creates risks. It covers cyber-crime types, information system security controls, professional ethics, and ICT policy that organizations adopt to protect data and behave responsibly.

* ⚠️ **Cyber-crime:** Information technology can be misused for identity theft, phishing, piracy, click fraud, and hacking.
* 🛡️ **Security Measures:** Anti-virus software, strong authentication, backups, and biometrics reduce threats to system resources.
* 🔑 **Access Control:** Combining passwords with mobile verification and security questions limits unauthorized access.
* ⚖️ **Ethics:** A code of ethics makes MIS professionals accountable for using information systems responsibly.
* 📜 **ICT Policy:** Written guidelines govern hardware, licensed software, passwords, and acceptable technology use.

[ Read More ](javascript:void%280%29;) 

[![Ethical and Security Issues in Information System](https://www.guru99.com/images/ethical-and-security-issues-in-mis.png)](https://www.guru99.com/images/ethical-and-security-issues-in-mis.png)

Information systems have made many businesses successful today. Some companies such as Google, Facebook, eBay, etc., would not exist without information technology. However, improper use of information technology can create problems for the organization and employees.

Criminals gaining access to credit card information can lead to financial loss to the owners of the cards or the financial institution. Using organization information systems, i.e., posting inappropriate content on Facebook or Twitter using a company account, can lead to lawsuits and loss of business.

This tutorial will address such challenges that are posed by information systems and what can be done to minimize or eliminate the risks.

## Cyber-crime

Cyber-crime refers to the use of information technology to commit crimes. Cyber-crimes can range from simply annoying computer users to huge financial losses and even the loss of human life. The growth of smartphones and other high-end [Mobile](https://www.guru99.com/mobile-testing.html) devices that have access to the internet has also contributed to the growth of cyber-crime.

[](https://www.guru99.com/images/MIS/012316%5F0855%5FEthicalandS1.jpg)

### Types of cyber-crime

#### Identity theft

Identity theft occurs when a cyber-criminal impersonates someone else’s identity to practice malfunction. This is usually done by accessing personal details of someone else. The details used in such crimes include social security numbers, date of birth, credit and debit card numbers, passport numbers, etc.

Once the information has been acquired by the cyber-criminal, it can be used to make purchases online while impersonating himself to be someone else. One of the ways that cyber-criminals use to obtain such personal details is phishing. **Phishing involves creating fake websites that look like legitimate business websites or emails**.

For example, an email that appears to come from YAHOO may ask the user to confirm their personal details, including contact numbers and email password. If the user falls for the trick and updates the details and provides the password, the attacker will have access to the personal details and the email of the victim.

If the victim uses services such as PayPal, then the attacker can use the account to make purchases online or transfer funds.

Other phishing techniques involve the use of fake Wi-Fi hotspots that look like legitimate ones. This is common in public places such as restaurants and airports. If an unsuspecting user logs on to the network, then cyber-criminals may try to gain access to sensitive information such as usernames, passwords, credit card numbers, etc.

According to the US Department of Justice, a former state department employee used email phishing to gain access to email and social media accounts of hundreds of women and accessed explicit photos. He was able to use the photos to extort the women and threatened to make the photos public if they did not give in to his demands.

#### Copyright infringement

Piracy is one of the biggest problems with digital products. Websites such as the Pirate Bay are used to distribute copyrighted materials such as audio, video, software, etc. Copyright infringement refers to the unauthorized use of copyrighted materials.

Fast internet access and reducing costs of storage have also contributed to the growth of copyright infringement crimes.

#### Click fraud

Advertising companies such as Google AdSense offer pay-per-click advertising services. Click fraud occurs when a person clicks such a link with no intention of knowing more about the click but to make more money. This can also be accomplished by using automated software that makes the clicks.

#### Advance Fee Fraud

An email is sent to the target victim that promises them a lot of money in favor of helping them to claim their inheritance money.

In such cases, the criminal usually pretends to be a close relative of a very rich, well-known person who died. He/she claims to have inherited the wealth of the late rich person and needs help to claim the inheritance. He/she will ask for financial assistance and promise to reward later. If the victim sends the money to the scammer, the scammer vanishes and the victim loses the money.

#### Hacking

Hacking is used to by-pass security controls to gain unauthorized access to a system. Once the attacker has gained access to the system, they can do whatever they want. Some of the common activities done when a system is hacked are:

* Install programs that allow the attackers to spy on the user or control their system remotely.
* Deface websites.
* Steal sensitive information. This can be done using techniques such as [SQL](https://www.guru99.com/sql.html) Injection, exploiting vulnerabilities in the database software to gain access, social engineering techniques that trick users into submitting IDs and passwords, etc.

#### Computer virus

Viruses are unauthorized programs that can annoy users, steal sensitive data, or be used to control equipment that is controlled by computers.

### RELATED ARTICLES

* [MIS Tutorial ](https://www.guru99.com/mis-tutorial.html "MIS Tutorial")
* [MCSA Certification: Course Syllabus & Exam Tutorial ](https://www.guru99.com/mis-microsoft-certified-solutions.html "MCSA Certification: Course Syllabus & Exam Tutorial")
* [Decision Support System (DSS): Demo PoS for a Retail Store ](https://www.guru99.com/mis-demo-retail-store.html "Decision Support System (DSS): Demo PoS for a Retail Store")
* [Need & Importance of MIS (Management Information System) ](https://www.guru99.com/mis-objectives-needs.html "Need & Importance of MIS (Management Information System)")

## Information system Security

MIS security refers to measures put in place to protect information system resources from unauthorized access or being compromised. Security vulnerabilities are weaknesses in a computer system, software, or hardware that can be exploited by the attacker to gain unauthorized access or compromise a system.

People, as part of the information system components, can also be exploited using social engineering techniques. The goal of social engineering is to gain the trust of the users of the system.

Let’s now look at some of the threats that information systems face and what can be done to eliminate or minimize the damage if the threat were to materialize.

[](https://www.guru99.com/images/MIS/012316%5F0855%5FEthicalandS2.jpg)

**Computer viruses** – these are malicious programs as described in the above section. The threats posed by viruses can be eliminated, or the impact minimized, by using Anti-Virus software and following the laid-down security best practices of an organization.

**Unauthorized access** – the standard convention is to use a combination of a username and a password. Hackers have learnt how to circumvent these controls if the user does not follow security best practices. Most organizations have added the use of mobile devices such as phones to provide an extra layer of security.

Let’s take Gmail as an example. If Google is suspicious of the login on an account, they will ask the person about to log in to confirm their identity using their Android-powered mobile devices, or send an SMS with a PIN number which should supplement the username and password.

If the company does not have enough resources to implement extra security like Google, they can use other techniques. These techniques can include asking questions to users during signup, such as what town they grew up in, the name of their first pet, etc. If the person provides accurate answers to these questions, access is granted into the system.

**Data loss** – if the data center caught fire or was flooded, the hardware with the data can be damaged, and the data on it will be lost. As a standard security best practice, most organizations keep backups of the data at remote places. The backups are made periodically and are usually put in more than one remote area.

**Biometric Identification** – this is now becoming very common, especially with mobile devices such as smartphones. The phone can record the user’s fingerprint and use it for authentication purposes. This makes it harder for attackers to gain unauthorized access to the mobile device. Such technology can also be used to stop unauthorized people from getting access to your devices.

## Information system Ethics

Ethics refers to rules of right and wrong that people use to make choices to guide their behaviors. Ethics in MIS seek to protect and safeguard individuals and society by using information systems responsibly. Most professions usually have a defined code of ethics or code of conduct guidelines that all professionals affiliated with the profession must adhere to.

In a nutshell, a code of ethics makes individuals acting on their free will responsible and accountable for their actions. An example of a Code of Ethics for MIS professionals can be found on the British Computer Society (BCS) website.

## Information Communication Technology (ICT) policy

An ICT policy is a set of guidelines that defines how an organization should use information technology and information systems responsibly. ICT policies usually include guidelines on:

* Purchase and usage of hardware equipment and how to safely dispose of them.
* Use of licensed software only, and ensuring that all software is up to date with the latest patches for security reasons.
* Rules on how to create passwords (complexity enforcement), changing passwords, etc.
* Acceptable use of information technology and information systems.
* Training of all users involved in using ICT and MIS.

## FAQs

🤖 How does AI help detect cyber threats in information systems?

AI monitors network traffic and user behavior to flag anomalies such as unusual logins, phishing emails, and malware patterns in real time. It speeds up detection and response, though security teams still confirm and act on the alerts.

🧠 Can AI improve data privacy protection?

Yes. AI can classify sensitive data, mask personal information, and detect policy violations before data leaks occur. However, organizations must ensure the AI itself is trained and governed responsibly so it does not create new privacy risks.

❓ What is the difference between a threat and a vulnerability?

A vulnerability is a weakness in a system, such as unpatched software. A threat is a potential event that could exploit that weakness, such as a hacker or virus. Risk arises when a threat meets a vulnerability.

🔐 What is two-factor authentication?

Two-factor authentication adds a second proof of identity beyond a password, such as a code sent to a phone or a fingerprint. Even if a password is stolen, the extra factor helps block unauthorized access.

#### Summarize this post with:

ChatGPT Perplexity Grok Google AI 

**Stay Updated on AI** **Get Weekly AI Skills, Trends, Actionable Advice.** 

##### Sign up for the newsletter

Subscribe for Free 

You have successfully subscribed.  
Please check your inbox. 

![AI-Newsletter]() Chosen by over **350,000+** professionals 

[Scroll to top ](#wrapper)Scroll to top 

× 

Toggle Menu Close 

Search for: 

Search

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.guru99.com/#organization","name":"Guru99","sameAs":["https://www.facebook.com/Guru99Official","https://twitter.com/guru99com"],"logo":{"@type":"ImageObject","@id":"https://www.guru99.com/#logo","url":"https://www.guru99.com/images/guru99-logo-v1-150x59.png","contentUrl":"https://www.guru99.com/images/guru99-logo-v1-150x59.png","caption":"Guru99","inLanguage":"en-US"}},{"@type":"WebSite","@id":"https://www.guru99.com/#website","url":"https://www.guru99.com","name":"Guru99","publisher":{"@id":"https://www.guru99.com/#organization"},"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https://www.guru99.com/images/ethical-and-security-issues-in-mis.png","url":"https://www.guru99.com/images/ethical-and-security-issues-in-mis.png","width":"700","height":"250","caption":"Ethical &amp; Security Issues in MIS","inLanguage":"en-US"},{"@type":"BreadcrumbList","@id":"https://www.guru99.com/mis-ethical-social-issue.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":"1","item":{"@id":"https://www.guru99.com","name":"Home"}},{"@type":"ListItem","position":"2","item":{"@id":"https://www.guru99.com/mis","name":"MIS"}},{"@type":"ListItem","position":"3","item":{"@id":"https://www.guru99.com/mis-ethical-social-issue.html","name":"Ethical &#038; Security Issues in Information System"}}]},{"@type":"WebPage","@id":"https://www.guru99.com/mis-ethical-social-issue.html#webpage","url":"https://www.guru99.com/mis-ethical-social-issue.html","name":"Ethical &#038; Security Issues in Information System","dateModified":"2026-08-06T16:37:05+05:30","isPartOf":{"@id":"https://www.guru99.com/#website"},"primaryImageOfPage":{"@id":"https://www.guru99.com/images/ethical-and-security-issues-in-mis.png"},"inLanguage":"en-US","breadcrumb":{"@id":"https://www.guru99.com/mis-ethical-social-issue.html#breadcrumb"}},{"@type":"Person","@id":"https://www.guru99.com/author/atlas","name":"Atlas Phoenix","description":"I am Atlas Phoenix, an MIS Specialist, offering expert guidance to help you streamline your management information systems with practical solutions.","url":"https://www.guru99.com/author/atlas","image":{"@type":"ImageObject","@id":"https://www.guru99.com/images/atlas-phoenix-author.png","url":"https://www.guru99.com/images/atlas-phoenix-author.png","caption":"Atlas Phoenix","inLanguage":"en-US"},"worksFor":{"@id":"https://www.guru99.com/#organization"}},{"articleSection":"MIS","headline":"Ethical &#038; Security Issues in Information System","description":"Information systems have made many businesses successful today. Some companies such as Google, Facebook, EBay, etc. would not exist without information technology. However, improper use of information","keywords":"mis","speakable":{"@type":"SpeakableSpecification","cssSelector":[".entry-title",".summary"]},"@type":"Article","author":{"@id":"https://www.guru99.com/author/atlas","name":"Atlas Phoenix"},"dateModified":"2026-08-06T16:37:05+05:30","image":{"@id":"https://www.guru99.com/images/ethical-and-security-issues-in-mis.png"},"copyrightYear":"2026","name":"Ethical &#038; Security Issues in Information System","subjectOf":[{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What is the difference between cybersecurity and cybercrime?","acceptedAnswer":{"@type":"Answer","text":"Cybercrime is any illegal act committed using information technology, such as hacking or fraud. Cybersecurity is the practice of protecting systems, networks, and data from such attacks \u2014 one is the threat, the other is the defense."}},{"@type":"Question","name":"What is the CIA triad in information system security?","acceptedAnswer":{"@type":"Answer","text":"The CIA triad names the three core security goals: Confidentiality keeps data private, Integrity keeps it accurate, and Availability keeps it accessible to authorized users. Most security controls aim to protect one or more of these."}},{"@type":"Question","name":"What is social engineering in information security?","acceptedAnswer":{"@type":"Answer","text":"Social engineering manipulates people, rather than technology, into revealing information or granting access. Attackers exploit trust through phishing emails, fake calls, or impersonation, so user awareness training is a key line of defense."}},{"@type":"Question","name":"Is cybercrime a punishable offense?","acceptedAnswer":{"@type":"Answer","text":"Yes. Most countries have laws against hacking, identity theft, fraud, and copyright infringement. Offenders can face fines, imprisonment, or both, and affected organizations may also pursue civil claims for damages."}},{"@type":"Question","name":"How does encryption protect information systems?","acceptedAnswer":{"@type":"Answer","text":"Encryption scrambles data into unreadable code that only an authorized key can unlock. Even if attackers intercept or steal the data, they cannot read it, which protects passwords, payments, and confidential records."}},{"@type":"Question","name":"How is AI used to prevent cybercrime?","acceptedAnswer":{"@type":"Answer","text":"AI monitors network traffic, flags unusual behavior, and blocks threats in real time. Machine learning models learn from past attacks to detect new ones, helping security teams respond faster than manual methods allow."}},{"@type":"Question","name":"Can AI and machine learning detect phishing and fraud?","acceptedAnswer":{"@type":"Answer","text":"Yes. AI and machine learning scan emails, URLs, and transactions for suspicious patterns, then automatically quarantine or block them. These intelligent filters catch many scams that older rule-based systems miss."}},{"@type":"Question","name":"What security and ethical risks do AI tools like Copilot and GPT introduce?","acceptedAnswer":{"@type":"Answer","text":"AI assistants such as Copilot and GPT can leak confidential data entered as prompts, generate insecure code, or spread convincing scams. Responsible use, human review, and clear policies help reduce these risks."}}]}],"@id":"https://www.guru99.com/mis-ethical-social-issue.html#schema-1129557","isPartOf":{"@id":"https://www.guru99.com/mis-ethical-social-issue.html#webpage"},"publisher":{"@id":"https://www.guru99.com/#organization"},"inLanguage":"en-US","mainEntityOfPage":{"@id":"https://www.guru99.com/mis-ethical-social-issue.html#webpage"}}]}
```
