Saturday, 7 June 2014

Data Flow Charts (M1)

High Level

Low Level

Code of Practice (p3, m2)

In order for companies to get optimal working ability and prevent ethical problems in the work place the companies create a code of practice for use of a computer in the organisation.

Examples of these practices are

Email

The code of practice prohibits the use of emails that contain verbal abuse directed at a staff member, using emails to harass staff members, spamming unimportant emails to people in the business, spamming emails to people it has nothing to do with. It also allows a small amount of private emails to be sent to friends, family and love ones but prohibits constant emailing to external sources.

Use of internet

The code of practice prohibits the browsing of inappropriate or the over use of personal websites. Inappropriate entails pornography, gambling, piracy websites and illegal purchasing websites, as over use of personal websites entails over using websites like Facebook or Steam while working. However most company web servers have blocking software on it to prevent viewing of these websites.


The encouragement of whistle blowing

Whistle blowing means that if anybody is misusing their use of the computer a large portion of the time and gets spotted doing this on a regular basis, the spotter is encouraged to tell management especially if it is the the people who enforce the code of practice or doing something illegal with in the work place. an example of this is when a CIA agent in the 1980s was selling drug evidence to make a profit when one of his work colleagues found out he reported it to his boss and the agent was arrested.  


Computer Misuse Act (p3, m2)

Is the act that was created to prevent computers from being used for hacking or causing havoc with malicious intent. The act was created to protect peoples private affairs and prevent total chaos for organisations who had been targeted by hackers the act is then reinforced by the data protection act which give individuals and companies the promise of no private information leaks.

A case of this act being broken is the organisation of the New of the World who were hacking into celebrities and prominent members of societies phone lines and computers in order to steal private information for news stories. However after the scandal was found out the a large amount of members in the organisation gained a prison sentence for breaking the computer misuse act and the Freedom of information act as well as the data protection act.

The act also protect companies digital products by making it illegal for distribution of digital pirated material. However only countries that have similar acts to this can prevent internet piracy as our country can only prevent the distribution here in the UK and can only block foreign websites.

There are three principles to the computer misuse act.

Unauthorised access to computer material: This principle means that accessing a persons personal information from their computer without authorisation and then looking at their information, stealing it, or deleting it, can result in 6 months imprisonment and  a large fine.

Unauthorised access with intent to commit or facilitate a crime: This is similar to the first principle. However, the person who does not have access to the information is looking to commit a crime, this being stealing bank account information to gain money or stealing anything else they don't have access to and using it for their personal gain. The result of doing so can lead to five years imprisonment and once again a large fine.

Unauthorised Modification of computer material: This is also similar to the first principle. However, this principle is if the unauthorised person wishes to modify files or delete them from another user or even creating a computer virus for malicious intent to steal or destroy information and same as the last principle you can receive 5 years imprisonment.

Data related to use of information (Freedom of information act) (p3, m2)

Freedom of information act


Is a law that gives the public or companies to ask information that is based  on them from public authorities such as government departments. The information that they can ask for can range from computer files, printed documents, photographs and any kind of digital recording. However if a member of the public wishes to see the information that has been collected on them they need to make a request under the data protection act if they wish to gain access to the information.

The freedom of information act also makes it mandatory for public authorities to publish what they are doing e.g. decisions, changes, and happenings. This also affect private organisation as they are obliged to give information about their company to everyone so they actually know what they are doing rather than doing something completely different  which that organisation is either not suppose to do or are doing what the comapny was not made for e.g. a shoe company that sells shampoo instead of shoes.

Wednesday, 4 June 2014

Data related to use of information (Data Protection act) (p3, m2)

Data protection act

The data protection act is a law that secures personal information about people who interact with a company through employment or externally. Data protection can protect personal information such as payment details, contact information and personal details such as mental state. The information is gathered by a  data controller who collects the most important data that is vital for the organisation and what the data will be used for.

There are several principles for the data protection, these are the following principles.

Used fairly and lawfully

This is where the person who has had the information collected on them has the right to know that information is being collected on them and what the information is being used as the end result.


Personal data can be held only for specified and lawful purposes

Is when the collector of the information must state what they are using the information or and actually use the information towards that reason and not any other reason not specified by the company they work for.

Personal data should be adequate, relevant and not excessive for the required purpose


This is where the collector of the information must collect relevant information about the individual they are collecting information about. An example of this where you would collect information about his contact information or name which is relevant, but you would not collect information about the individuals eye color.

Personal data should be accurate and kept up-to-date.

This is where stored information on a individual must be kept up to date so that it remains relevant and useful. An example of this is a employee could change there contact details or second name, another example could be that they live at a address that is wrong so it would have to be corrected so that the information Is accurate so it would be important to keep it up to date. 

Personal data should not be kept for longer than is necessary.

This is where information that is no longer needed should be removed as it becomes irrelevant or not useful anymore. an example of this is CVs as you are supposed to keep it for five months as it can take up storage and they already have your personal details on log which you provide from your CV.

 

Data must be processed in accordance with the rights of the data subject.

This is where the individual who has data on him/her has the right to see that data at any time so that they may take a copy, change or just view.

Appropriate security measures must be taken against unauthorized access.

This is where data on a subject are protected from people who do not have access to the data on the subject this is done by taking security procedures such as making sure that you have anti hacking procedures or taking precautions that don't let people see data about people they shouldn't know about.

Personal data cannot be transferred to countries outside the E.U. unless the country has similar legislation to the Data protection act.

Is where the company if they wish to share information with other companies outside of it's own country can only share the information with countries that have similar law to the data protection act otherwise your are sharing information with people from a coutry that do not have access to the information.