No Duty of Care: The Governance of ICT

Marghanita da Cruz, Principal Consultant, Ramin Communications

ET GOVICT2008 - A Conference on the Ethical Governance of ICT and the Role of Professional Bodies
University House, Australian National University
1 - 2 May 2008

Outline

April's news

Straw Poll on ICT Roles and Responsiblities

Australian Standard for Corporate Governance of ICT

ISO/IEC 38500 based on As8015 is due to be published at the end of May 2008

Illustration of Corporate Governance of ICT by Joel Tarling

AS8015 Principles

  1. Establish Responsibilities
  2. Plan ICT
  3. Acquire ICT validly
  4. Ensure that ICT performs
  5. Ensure ICT conforms
  6. Ensure ICT respects human factors

AS8015 Model

Other Standards & Better Practice Guidelines

OECD Security of Information Systems and Networks Principles

Financial Legislation

ICT Regulation and Legislation

Privacy Act 1988 Personal Information Principles

Experience of Online Credit Card Fraud (aic.gov.au)

Table 3: Number and percent of victims of online credit card fraud by business type in Australia

 Currently trading onlinePreviously traded online
Business typen% victimsn% victims
Florists29628240
Book sellers 181431533
Recorded music retailers77261517
Toy and game retailers72339100
Computer hardware retailers215303250
Total841329534
Source: Australian Institute of Criminology, Online credit card fraud against small business 2003 [computer file, weighted data]

Internet Scams (fido.gov.au)

Ethics pop up all over the place

What could ICT professional ethics offer

References & Further Reading

  1. Straw Poll of Roles and Responsibilities
  2. AS8015-2005 - Australian Standard for Corporate Governance of Information and Communication Technology (ICT)
  3. Survey of IT Governance Instruments, Standards, Guides, Regulations, Laws and Frameworks - ramin.com.au/itgovernance
  4. Ethics, Mike Bowern, Information Age 14/02/2006
  5. Achieving value from ICT: key management strategies (2005)
  6. Building ethics into quality assurance Craig McDonald, Information Age (18/08/2005)
  7. ICT Integrity: bringing the ACS code of ethics up to date, Michael Bowern, Oliver Burmeister, Don Gotterbarn, John Weckert
  8. Striking a balance between Ethics and IT Governance Graeme Pye, Matthew Warren
  9. AS8015-2005 - Australian Standard for Corporate Governance of Information and Communication Technology (ICT) - ramin.com.au/itgovernance/as8015.html
  10. OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security - www.oecd.org
  11. Types of fraud relating to other purchases - www.aic.gov.au
  12. Do Not Call Register - www.donotcall.gov.au
  13. Spam & e-Security - www.acma.gov.au
  14. Protecting Australian Families Online - www.netalert.gov.au
  15. Information Privacy Principles under the Privacy Act 1988 - www.privacy.gov.au
  16. Digital switchover date confirmed (18 December 2007) - www.minister.dbcde.gov.au/
  17. The whole-of-government IT outsourcing initiative - www.aph.gov.au
  18. Unisys Australia Ltd v RACV Insurance Pty Ltd & Anor [2004] VSCA 81 (14 May 2004) - www.austlii.edu.au
  19. Australian Customs - more flak than facts? (14/02/2006) - www.infoage.idg.com.au
  20. Going cheap: One.Tel's last jewel (July 14, 2004) - www.smh.com.au
  21. MoneyTree Venture Capital Profile for United States - PricewaterhouseCoopers/Venture Economics/NVCA - vx.thomsonib.com
  22. ASIC reaches agreement with John Greaves in One.Tel proceedings (6 September 2004) - www.asic.gov.au
  23. Former FAI officer sentenced (1 December 2006) - www.asic.gov.au
  24. ASIC commences investigation into Ansett (14 September 2001) - www.asic.gov.au
  25. Key superannuation information - www.ato.gov.au
  26. Values in the APS
  27. Corporate Law Economic Reform Program (CLERP 9) - www.asic.gov.au
  28. Principles of Good Corporate Governance and Best Practice Recommendations - www.asx.com.au
  29. www.acs.org.au/governance
  30. Australian Ethical Charter - austethical.com.au
  31. Malaysian Islamic Capital Market
  32. "Understanding and Managing Risk Attitude", Hilson and Murray-Webster
  33. Frameworks for IT Management
  34. Professionalisation, Ethics And Integrity Systems: Summary Account