Ethical Disclosure

In the course of an assessment or audit, circumstances may come forward, which might suggest that illegal, unethical or dangerous actions may have been committed by a person or persons within the organization's span of responsibilities or control.

8 slides · 4 min read · Domain 6

Slide 1

In many cases, the assessor is legally obligated to report the circumstance outside the organization to the proper authorities regardless of the actions or desires of the audited organization.

The assessment charter and organizational policy address should specify how these situations are to be documented, communicated and resolved. In the absence of a legal obligation, there may still be an ethical obligation for disclosure of some or all of these indicators or findings.

Non-Disclosure

Addressing a weakness in a system is often complicated when the weakness is discovered by an organization(s) who is not responsible or capable of addressing the weakness. This is not an unusual circumstance, particularly in the case of software vulnerabilities.

Depending on the nature of the discovery, public disclosure of the weakness may not be possible due to non- disclosure or other contractual agreements. Ethically, one can argue that disclosure to the affected party is required; contractually and legally, however, this can place the discovering party in jeopardy, either of compromising a potential civil or criminal investigation, of violating the privacy or data protection rights of an individual, or other violations.

Financial transactions, accounts, and account application data, for example, are in many cases prohibited from sharing with anyone other than duly authorized law enforcement and regulatory officials.

So called safe harbor programs have attempted to provide channels for financial and insurance communities to share threat and risk data, but these run afoul of GDPR and other data protection requirements. The bottom line is that in these circumstances, non-disclosure may be the only legal and ethical course of action.

Full Disclosure

Full disclosure implies that when a weakness is discovered, the individual or organization discovering the weakness should publicize the weakness as soon as possible to all potentially affected organizations.

Advocates for full disclosure argue that failing to immediately and fully disclose all vulnerabilities leaves some organizations at risk, and the public embarrassment from vendors suffers when poorly secured systems are publicized as such, which is sufficient to motivate vendors to remediate weaknesses.

Responsible Disclosure

Responsible disclosure implies that the individual discovering a weakness should report the weakness to the organization responsible for addressing the weakness and give that organization some time to address the weakness before public disclosure. Differences exist as to the appropriate length of time, but the concept is supported by individuals like Linus Torvalds (the creator of Linux) and organizations like Microsoft and Google.

Project Zero and the Vulnerabilities Equities Process (VEP)

Google's work has highlighted the divide between the advocates for responsible disclosure and the interests of proprietary software developers who want to control the release of vulnerability information. However, the threat of public disclosure has been effective. According to Project Zero's data, more than 95% of identified weaknesses are remediated within the time frame. Since the project has begun, multiple vendors have adjusted their patch processes and significantly decreased the length of time from identification to remediation.

In 2014, Google assembled a team of security researchers to search for and study previously unknown vulnerabilities in hardware and software. Project Zero researches popular software including mobile operating systems, web browsers, open source libraries and commercial software from a variety of vendors.

Acting within the Google vulnerability disclosure policy, the Project Zero team provide the details of the weaknesses to the company or development team responsible for the vulnerable system. The weakness is tracked, and if no patch or mitigation is made available within 90 days, Google will make the existence of the weakness publicly available.

Google's work stands in contrast to the actions of nation-state actors and black-hat bad actors searching for vulnerabilities, as the Google research is not performed for organizational gain. In the U.S.., the decision to disclose vulnerabilities known to various government agencies has been managed through an interagency process known as the Vulnerabilities Equities Process (VEP).

Through this process, case-by-case determinations are made to disclose vulnerabilities to support legal discovery or other governmental interests. The VEP has been criticized as lacking in transparency, but the interests of law enforcement and national security activities have generally been prioritized over full disclosure.

Mandatory Reporting

The circumstances uncovered by the assessor may require the assessor to report the circumstance to authorities. While the laws vary greatly as to what must be reported and by whom, computer crimes, particularly those involving minors, are often subject to mandatory reporting requirements in many jurisdictions.

Information security professionals including controls assessors and auditors must understand their legal obligations for reporting suspected criminal activity.

Whistleblowing

In other cases, the legal framework or the circumstance may not mandate reporting, but the individual feels ethically obligated to report the situation to the authorities. As with mandatory reporting, the methods for disclosure and the protections for whistleblowing vary between jurisdiction and circumstance.

As a result, the whistleblower may or may not have legal protection for the disclosure of proprietary information. The security professional is responsible for clarifying the legal status of whistleblowing in the applicable jurisdiction prior to disclosure.

Test this domain