Ethics for IT Workers and IT Users#

Behind every IT system are people who design, develop, manage, maintain, and use technology. Because IT workers interact with many different people, they are involved in several types of professional relationships. These include relationships with:

  • Employers

  • Clients

  • Suppliers

  • Other IT professionals

  • IT users

  • Society as a whole

These relationships must be properly managed because an IT worker often has access to important systems, confidential information, company resources, and technologies that can affect other people.

An ethical IT worker is therefore expected to act honestly, responsibly, fairly, professionally, and appropriately in each relationship. A simple way to understand this is: an IT worker does not work with technology alone. An IT worker works with people, organizations, information, and society. For example, imagine that a company hires a programmer to create an employee-management system. The programmer has to deal with the employer who hired them, the employees who will use the system, possibly a software supplier, other IT professionals, and ultimately society, because the system may handle people’s personal information. Therefore, technicall skill is not enough. Ethics and professionalism are equally important.

Relationship Between IT Workers and Employers#

The relationship between an IT worker and an employer is one of the most important professional relationships. When an employee accepts a job, both sides normally agree on important conditions such as:

  • Job position or title

  • Responsibilities

  • Expected performance

  • Salary

  • Working hours

  • Work location

  • Company benefits

  • Dress code

  • Company policies

  • Use of computers and networks

  • Protection of company information

These agreements establish what the employee and employer expect from each other.

Example

Imagine that Ana is hired as a Network Administrator. During her hiring process, the company tells her: “Your job is to maintain our network, troubleshoot problems, protect our systems, and make sure employees can access the resources they need.” Ana also agrees to follow the company’s rules, protect confidential information, and properly use company computers. This means their relationship is not simply:

Company → gives salary → employee → does work

It is actually a relationship involving mutual responsibilities and trust. The employer provides compensation, resources, and working conditions, while the employee provides skills, effort, responsibility, and professional service.

Company Policies and Rules#

Not everything between an employee and employer is necessarily written into the employment contract. Companies may have a policy and procedures manual or code of conduct explaining additional expectations. Company policies may cover vacation, sick leave, family emergencies, confidentiality, appropriate use of company computers, appropriate use of company networks, and other situations depending on the circumstances.

Example

An employee may ask, “Can I leave two hours early t oday if I make up these two hours tomorrow?” Whether this is allowed may depend on company policy or an agreement with the supervisor.

An employer also cannot simply order an IT worker to do something illegal.

Example

Suppose a manager tells an IT employee, “Change the testing records so it looks like our software passed all quality tests.” The employee should not do this simply because the manager is their boss. The source specifically gives the example that an employee cannot be required to perform something illegal, such as falsifying quality-assurance test results.

IT Workers as Stewards of Company Technology#

IT workers often have special access to an organization’s computers, servers, databases, networks, software, files, user accounts, and security systems. Because of this access, IT workers have a special responsibility. They can potentially protect the organization’s technology or abuse it. The source describes IT workers as stewards of an organization’s IT resources. They are expected to set an example and enforce policies concerning ethical IT use.

Example

Imagine an IT administrator discovers that they can access the payroll database. They could technically look at: “How much does my coworker earn?” But just because the system allows them to access something does not mean they have an ethical reason to access it. This is an important principle: Having access does not automatically mean having permission.

Software Piracy#

One major ethical problem involving IT workers and employers is software piracy.

Software piracy is the unauthorized copying, installation, distribution, or use of software.

Example

Imagine a company needs 20 licenses for a particular software program. Instead of buying 20 legitimate licenses, the IT department installs one illegally copied version on 20 computers. The company saves money in the short term, but it has violated the software licensing agreement.

Software piracy in corporate environments can sometimes be directly connected to IT employees because they may either allow piracy to occur or participate in it themselves.

Example

Imagine your group needs editing software for a school project. Someone says, “Don’t worry. I have a cracked version. Just install it.” Even though it may seen convenient and cheaper, the software was not legally obtained. The same principle applies in a company, except the consequences can be much more serious because organizations may use large numbers of computers and software licenses.

Trade Secrets#

A trade secret is valuable information that is generally unknown to the public and that a company takes measures to keep confidential.

Examples

  • Software source code

  • Hardware designs

  • Business plans

  • Product designs

  • Manufacturing processes

  • User-interface designs

  • Special formulas

Whistle-Blowing#

Whistle-blowing occurs when an employee brings attention to an organization’s illegal actions, dangerous practices, unethical behavior, negligence, abuse, and activities that threaten the public.

A whistle-blower may first try to report the problem internally. If management ignores or prevents the employee from correcting the problem, the employee may consider reporting it to an appropriate external authority.

Example

Imagine an IT employee discovers that a company’s system has a serious security vulnerability. The vulnerability could expose thousands of customers’ personal information. The employee reports it to management, “We need to fix this immediately.” But management responds, “Don’t worry about it. Fixing it will cost too much money.” If the company continues ignoring serious risk to the public, the employee may face an ethical dilemma about whether to report the problem through appropriate external channels.

Why is whistle-blowing difficult?

Because doing the right thing can sometimes have consequences for the employee. Whistle-blowers may face retaliation or even termination. So whistle-blowing is not simply, “Report your company whenever you disagree with them.” It involves serious ethical considerations, evidence, procedures, and the potential harm to the public.

Relationship Between IT Workers and Clients#

IT workers do not only work for employers. They may also work directly with clients. The IT worker provides something valuable, such as software, hardware, technical services, system development, and IT consulting. In return, the client provides things such as payment, information, access to necessary personnel, workspace, and cooperation. These expectations are normally documented in a contract and both sides have responsibilities.

Why is communication important?

The IT professional understands technology better, while the client understsands the organization’s actual needs better. Therefore, the client and IT worker must communicate and make decisions together. Decision-making is shared because clients depend on IT professionals for technical recommendations while IT professionals depend on clients for accurate information and informed choices.

Conflict of Interest#

A conflict of interest occurs when an IT worker’s personal or business interests conflict with the client’s best interests.

Example

Imagine that a company hires an IT consultant to determine which software would be best for its business. The consultant evaluates the available software. However, the consultant owns a company that sells one particular software product. The consultat says, “After evaluating everything, you should buy my company’s software.”

The problem is:

Is the recommendation really based on what is best for the client—or on what makes the consultant money?

This type of situation is potentially undermining the IT worker’s objectivity and the trustworthiness of their recommendation.

A professional should recommend what is best—not what benefits them personally.

Fraud and Misrepresentation#

Fraud involves obtaining goods, services, or property through deception or trickery. Fraudulent misrepresentation involves intentionally causing another person to rely on false information.

Four Elements of Fraudulent Misrepresentation:

  1. A false representation of an important fact was made.

  2. The person intended to deceive.

  3. The innocent party relied on the false information.

  4. The innocent party suffered harm.

Example

Imagine an IT company is developing an app. The project is supposed to be finished in six months. After four months, the project manager knows that the system is far behind schedule. Instead of telling the client, “We are experiencing major problems and the project will be delayed.” The manager says, “Everything is going perfectly. We will finish on time.” The client continues spending money based on that information. If the statement was intentionally false and caused harm, the situation can raise issues of fraudulent misrepresentation.

Breach of Contract#

A breach of contract occurs when one party fails to meet the terms of an agreement.

Example

An IT company signs a contract promising, “We will deliver the completed system by December 1.” December 1 arrives, but the company has not completed the system and has failed to meet its contractual obligations. That may constitute a breach of contract.

A material breach is more serious because the failure significantly affects the essential purpose of the contract.

Common reasons IT Projects Fail#

IT projects do not always fail because someone is intentionally unethical. Sometimes projects fail because of poor planning or commnunication.

Scope Creep

Occurs when the requirements or goals of a project continue to expand after the project has already begun.

Example

A client initially says, “We only need a basic online ordering system.”

Then later, “Can you also add delivery tracking?”

Then, “Can you add a loyalty program?”

Then, “Can you add an AI chatbot?”

The project that originally required six months may now require a year. More features mean more work, more money, more time, greater complexity.

Poor Communication

Happens when the client and IT team fail to clearly understand each other’s expectations.

Example

The client says, “Make the system user-friendly.”

The programmer interprets “user-friendly” differently from the client.

When the system is delivered, the client says, “This isn’t what we wanted.”

The programmer responds, “But you said it was user-friendly.”

The problem started because the requirements were not clearly communicated.

Delivery of an Obsolete Solution

Sometimes an IT company delivers a system that technically meets the original requirements, but newer technology becomes available before or during the project.

Example

A company spends months developing a system with a certain technology. Before launch, a competitor releases a much more advanced system with features that users strongly prefer.

The original system technically works, but it may no longer be competitive.

Legacy Systems

A legacy system is an older system or technology that an organization still depends on.

Example

A company wants to install a new accounting system. However, its old payroll database is 20 years old and uses a format that the new system cannot easily read. If the IT team was not told about this old system at the beginning, implementation becomes much more difficult.

Relationship Between IT Workers and Suppliers#

Suppliers are the one who provide hardware, software, network equipment, IT services, and technical products.

A healthy relationship with suppliers can encourage communication, new ideas, and cost-effective solutions. However, IT workers must also treat suppliers fairly.

Example

Suppose a company normally receives computers within one week. The IT manager suddenly says, “I need 100 computers tomorrow. If you can’t do it, I’m replacing you.” This is unreasonable if the supplier’s normal lead time is one week.

Good professional relationships involve fairness and reasonable expectations.

Bribery#

Suppliers sometimes try to influence IT employees by offering gifts or favors.

Bribery involves giving money, property, or favors to obtain a business advantage.

Example

A supplier offers an IT employee ₱50,000 if the employee chooses that supplier’s products. That is clearly unethical. But bribery is not always obvious.

A supplier might instead offer expensive dinners, free hotel stays, event tickets, golf tournament fees, or expensive gifts. Even gifts that appear innocent cna be perceived as bribery depending on the circumstances.

Internal Control#

Organizations use internal controls, which involves people, policies, processes, and procedures, to help prevent mistakes, fraud, and unethical activities. These controls help ensure that operations are effective, financial information is reliable, and laws and regulations are followed.

Policy

The rule.

Example

“Customer payments must be properly recorded.”

Process

The series of activities.

Example

Receive payment → record payment → deposit payment → update account.

Procedure

Exact instructions.

Example

“After receiving a payment, log into the accounting system, enter the customer’s account number, enter the amount, attach the receipt, and submit the transaction.”

Separation of Duties#

Different people should handle different parts of a financial transaction; if one person controls everything, it becomes easier to commit fraud and hide it.

Example

Imagine one employee is responsible for receiving money, approving refunds, depositing the money, and reconciling the bank account.

That person could potentially steal money and manipulate the records to hide it. Instead, responsibilities should be divided among different people.

Relationship Between IT Workers and Other Professionals#

IT workers do not work in isolation. They work alongside other professionals. Professionals generally have a responsibility to maintain the reputation and standards of their profession. Experienced professionals can also act as mentors to newer professionals.

Résumé Inflation#

Résumé inflation means exaggerating or lying about your qualifications.

Example

Imagine someone knows only basic Excel but writes, “Advanced Excel expert with extensive data analytics experience.” They might get the job.

But what happens when the employer gives them an advanced Excel task? They cannot perform it and creates problems for the employee, employer, coworkers, and clients.

Inappropriate Sharing of Corporate Information#

IT professionals may have access to sensitive information. Sharing this information with people have no legitimate need to know can violate privacy and confidentiality.

Example

Imagine you work in IT and accidentally discover your coworker’s salary. You tell your friend, “Guess how much our coworker earns!”

Even though you did not steal money or change anything, you improperly disclosed private information. The fact that you can see the information does not mean you have the right to share it.

Relationship Between IT Workers and IT Users#

An IT user is someone who uses hardware or software products. IT workers have a responsibility to understand user’s needs, abilities, limitations, and work requirements. They should provide systems and services that meet those needs while considering available time and budget.

Example

Imagine a hospital asks an IT team to create a patient-record system.

The IT workers should not simply think, “What software do we know how to build?”

They should ask, “What does the nurse need? What does the doctor need? What information needs to be quickly accessible? How can we make the system easy and safe to use?”

The technology should serve the user, not the other way around.

Relationship Between IT Workers and Society#

IT workers do not only have responsibilities toward their employers and clients. Their work can affect ordinary members of society. Modern society depends heavily on information systems.

A computer system may control of support:

  • Transportation

  • Healthcare

  • Banking

  • Communication

  • Manufacturing

  • Energy

  • Public services

Example

Imagine a software engineer develops software used to monitor a hospital patient’s life-support equipment.

If the software has a serious error, this is no longer just “The computer program has a bug.” It could potentially become “A person’s life is at risk.”

That is why IT professionals have responsibilities that go beyond simply pleasing their employer.

Encouraging IT Workers’ Professionalism#

A professional possesses the skills, judgment, and work habits expected from someone trained and experienced to perform their job properly.

A professional It worker should:

  • Be skilled in their area

  • Follow high ethical and moral standards

  • Produce quality work

  • Keep commitments

  • Communicate effectively

  • Help train less-experienced people

Example

There is a difference between “I finished the system. I don’t care if there are problems.” and “I finished the system, tested it, documented the issues, informed the client about limitations, and will help address problems.”

Professional Code of Ethics#

A professional code of ethics is a collection of principles and values that guide how members of a profession should behave. It helps professionals determine what is responsible, ethical, acceptable, and unacceptable.

Laws alone cannot answer every ethical question, and a code of ethics also cannot provide an answer to every possible dilemma. However, it provides important guidance.

Example

Suppose something is technically legal but still questionable. A professional code of ethics can encourage an IT worker to ask, “Even if I am legally allowed to do this, is it responsible?”

That is the difference between simply following the law and thinking ethically.

Benefits of a Code of Ethics#

Ethical decision-making

It gives professionals common values to use when making difficult decisions.

High standards

It reminds professionals of their responsibilities when workplace pressure encourages them to compromise.

Public trust

People are more likely to trust professionals who demonstrate honesty and integrity.

Evaluation benchmark

Professionals can use the code to evaluate their own behavior and the behavior of their colleagues.

Professional IT Organizations#

Association for Computing Machinery (ACM)

The ACM is a major computing professional organization concerned with advancing computing and promoting professional and ethical standards.

ACM helps computing professionals learn, network, share knowledge, develop professionally, and follow ethical standards.

IEEE Computer Society (IEEE-CS)

The IEEE Computer Society is part of IEEE and focuses on electrical, electronic, and information technologies and sciences. It supports conferences, research, publications, student chapters, technical committees, and standards work.

Association of Information Technology Professionals (AITP)

AITP provides seminars, conferences, networking, information about IT users, and professional development. It also has a code of ethics and standards of conduct.

SANS Institute

The SANS institute focuses heavily on information security training and certification. It provides training and resources for people such as security managers, network administrators, auditors, and other cybersecurity professionals.

Certification#

A certification indicates that a professional has demonstrated a particular set of skills, knowledge, or abilities according to the certifying organization. Certification is generally voluntary, unlike licensing, which can be legally required.

Example

Suppose Maria wants to work in cybersecurity.

She may obtain a cybersecurity certification to demonstrate that she has studied and passed an examination covering certain security skills.

However, certification does not automatically mean someone is an excellent employee. A certificate proves certain knowledge or skills, but experience, judgment, communication, and professionalism still matter.

Note

Certification cannot replace experience or guarantee job performance.

Vendor Certifications#

Companies such as Cisco, IBM, Microsoft, SAP, and Oracle offer certifications related to their products. These can be useful when a job specifically requires expertise with a particular technology.

Example

If a company primarily uses Cisco networking equipment, having a relevant Cisco certification may help demonstrate knowledge of that technology.

However, vendor certifications can sometimes be narrowly focused on one company’s technology.

Licensing of IT Professionals#

Important

Certification and licensing are not the same thing.

Certification

Usually demonstrates “I have these skills according to this certifying organization.”

Licensing

Generally means “The government has legally authorized me to practice this profession or activity under specified requirements.”

Why License IT Workers?#

The argument for licensing becomes stronger as technology becomes more connected to public safety. The failure of some critical IT systems can potentially cause serious injury or death.

Example

Imagine software controlling the braking system of a vehicle.

If the programmer makes a serious mistake, the consequence isn’t simply “The app crashed.” It could be “The vehicle failed to stop.”

This demonstrates why professional competence and ethical responsibility are important.

Eight Principles of Software Engineering Ethics#

Public

Software engineers should act consistently with the public interest.

Example

Do not release software known to create serious safety risks.

Client and Employer

Act in the best interests of the client and employer while still considering the public interest.

Example

Do good work for your company, but do not help the company harm the public.

Product

Software products should meet high professional standards.

Example

Proeprly test software before releasing it.

Judgment

Maintain integrity and independence in professional judgment.

Example

Don’t recommend a product simply because someone offered you money.

Management

Managers should have ethical approaches to software development and maintenance.

Example

A manager should not pressure employees to hide serious software problems.

Profession

Help maintain the integrity and reuptation of the IT profession.

Example

Do not lie about your qualifications.

Colleagues

Treat colleagues fairly and support them.

Example

Help a new programmer learn instead of intentionally allowing them to fail.

Self

Continue learning and promote ethical professional practice.

Example

Keep updating your skills because technology constantly changes.

IT Professional Malpractice#

Negligence means failing to do something a reasonable person would do, or doing something a reasonable person would not do.

Duty of care means having an obligation to protect people from unreasonable harm or risk.

Example

Imagine an IT professional is responsible for maintaining a company’s database.

They know that backups are required. However, they intentionally ignore the backup procedure for months. One day, the database is destroyed and millions of customer records are lost.

The question becomes: “Did the IT professional fail to act with the level of care expected from someone in that position?”

This is where negligence and professional responsibility become important.

When a professional breaches their duty of care and that negligence causes harm, this can be referred to as professional malpractice.

Common Ethical Issues for IT Users#

Ethical responsibilities do not belong only to IT professionals—IT users also have ethical responsibilities.

Software Piracy

An employee may copy software from their work computer and install it on their personal computer. They might think, “I work for the company, so I should be allowed to use it at home.” But if the software license does not permit that additional installation, it may still be piracy.

Inappropriate Use of Computing Resources

Company computers and networks are provided primarily for legitimate work purposes. Using them excessively for unrelated activities can waste working time, reduce productivity, consume company resources, create security risks, and create a hostile or inappropriate workplace.

Example

Imagine an employee spends four hours during work watching videos, playing online games, browsing social media, or chatting while their assigned work remains unfinished.

The computer may belong to the company, but the bigger issue is that company time and resources are being misused.

Inappropriate Sharing of Information

Organizations store huge amounts of sensitive information.

Private information may include:
  • Salary

  • Attendance

  • Health records

  • Performance ratings

  • Phone numbers

  • Addresses

  • Credit card information

Confidential company information may include:
  • Business strategies

  • Product formulas

  • Sales plans

  • Research

  • Staffing plans

  • Manufacturing processes

Sharing this information without authorization can violate privacy and potentially harm the organization.

Example

Imagine you work in HR or IT.

You discover that your coworker is receiving a certain salary. You send a screenshot of their payroll record to your friend. Even if your friend promises “I won’t tell anyone”, you have still improperly shared private information.

How Organizations Encourage Ethical IT Use#

Organizations cannot completely eliminate unethical behavior. However, they can establish systems that make ethical behavior clearer and unethical behavior harder.

Acceptable Use Policy#

An Acceptable Use Policy (AUP) is a document explaining what users are allowed and not allowed to do when using an organization’s computing and network resources.

Five Important Elements of an Effective AUP#

Purpose

Why does the policy exist?

Example

To protect company systems and information.

Scope

Who and what does the policy cover?

Example

All employees using company computers and networks.

Policy

What is acceptable and unacceptable?

Example

Acceptable: Using company email for legitimate business communication.

Unacceptable: Installing unauthorized software.

Compliance

Who checks whether people are following the policy?

Sanctions

What happens when someone violates it?

Example

Warning → Suspension → Loss of access → Termination

Limiting Access to Information#

Organizations should not automatically give every employee access to every piece of information. Instead, employees should have access to the information they need to perform their jobs.

Example

A sales manager may need access to sales data. But they probably do not need access to employee medical records, payroll records, secret product formulas, and research and development information.

Firewalls#

A firewall is a hardware, software, or a combination of both that helps protect an organization’s network from unauthorized access. It acts as a line of defense between an organization’s internal network and the Internet.

Example

Think of a firewall like a security guard at the entrance of a building.

The guard asks, “Who are you? Are you allowed inside? Where are you going?”

Similarly, a firewall helps control network traffic based on security rules.

Compliance#

Compliance means following established policies, guidelines, standards, specifications, laws, and regulations.

Example

If a company has a rule: “Customer information must be protected”, employees are expected to follow that rule. If a law also requires the organization to protect certain information, the company must comply with that law as well.

Why does compliance matter?

Failure to comply can lead to lawsuits, fines, civil penalties, criminal penalties, or damage to reputation.

Internal Audit#

Organizations may also have an internal audit department. Its responsibilities can include checking whether internal controls are effective, company assets are protected, policies are followed, laws and good practicies are followed, and information used for management decisions is reliable.

Example

Imagine a company says, “Only authorized employees can access customer data.”

An internal audit may investigate, “Is this rule actually being followed?”

They may examine records and controls to determine whether the system is working as intended.