Ethics Case Study

         Case Study: Smart homes for older people with disabilities


Dilemma - Part one:
You are the software engineer responsible for the integrity of Ferndale's system. During a routine inspection you discover several indicators suggesting a data breach may have occurred via some of the smart appliances, many of which have cameras and are voice-activated. Through the IoT, these appliances are also connected to Amazon Ring home security products - these ultimately link to Amazon, including supplying financial information and details about purchases.

1. Activity: Technical analysis – Before the ethical questions can be considered, the students might consider a number of immediate technical questions that will help inform the discussion on ethical issues. A sample data set or similar technical problem could be used for this analysis. For example:

    • Is it possible to ascertain whether a breach has actually happened and data has been accessed?
  • There must be an investigation to check out whether the breach has been happen or not. So that, we can also analyse if any system logs, network trafficking and other data's has taken of or not.
    • What data may have been compromised?
  • Personal data's might be compromised like: financial records, health records and so on.
    • Is a breach of this kind preventable, and could it be better prevented in the future?
  • Yes, it is preventable if any measure thing takes place. Yes, if the protection and safety of data and privacy would be more stronger and regular safety of audits and patch as well as the updates of the software that has been used.
    • Has the security been subject to a hack or is the data not secure?
  • With the breach result of being deliberate hacking or inherent security flaws is used as a ethical assessment. Even so there's an ethical duty that rectifies the security vulnerabilities and implement the strong measure to protect the data's from being accessed.
    • Has the problem now been rectified, and all data secured?
  • Yes, if the engineers prioritise the restoring of system and implement a strong measure security to prevent from any unauthorized access. And, communicating with the stakeholders regarding the action will maintain the trust and accountability among the people.

2. Activity: Identify legal and ethical issues. The students should reflect on what might be the immediate ethical concerns of this situation. This could be done in small groups or a larger classroom discussion.

Possible prompts:

    • Is there a risk that the breach comprised the residents’ personal details, financial information or even allowed remote and secret control of cameras? What else could have been compromised and what are the risks of these compromises? Are certain types of data more risky when breached than others? Why?
  • Yes, there is a risk if the breach compromises the resident's personal details, financial information and even allow the remote and secret control of cameras which might lead to the severe privacy and security concerns. Regarding to the personal and financial data breaches could identify the theft, financial fraud and invasion of privacy. Likewise, with the access of remote and cameras it can violate the resident autonomy and dignity as well as worsen the ethical implication.
    • What are the legal implications if there has been a breach? Do you, as a software engineer, have any duty to the residents at this point?
  • Legal implications included the violation of data protection regulations, potential lawsuits and regulatory fines. Yes, as a software engineer there is an ethical duty to prioritize the well being and rights of the residents. Including quickly addressing the breach, mitigating harm and going through the legal obligations for the protection of data's and privacy.
    • At the stage where the breach and its potential implications are unknown, should you tell the community and, if so, what should you say? Some residents aren’t always able to understand the technology or how it works, so they may be unlikely to recognise the implications of situations like this. Should you worry that it might cause them distress or create distrust in the integrity of the whole system if the possible data breach is revealed?
  • Yes, the resident's  deserves to get informed about the potential risks to their privacy and security, and it must be told with their level of understanding. And, it is also crucial to provide accurate information about the situation, risks and steps taken to address the breach. For that, engineer should be responsible for not causing any unnecessary distress or undermining trust in system and most importantly the resident's who may not have fully grasp the technical complexities that has been involved.
    • At the stage where the breach and its potential implications are unknown, is there anyone else you should inform? What should you tell them? Are there any risks you may be able to mitigate immediately? How?
  • Apart from the resident's, the related stakeholders including regular authorities, data protection agencies and the organization that looks after the smart home community are the ones that should be informed about this situation. And, they will be notify about the investigation of the breach, mitigate risks, and implementation of necessary safeguards. This might includes the temporary disable of affected smart appliances, enhancement of strong network security and conducting the forensic analysis to identify the extension of the breach.
    • Who owns the data collected on a person living in a smart home? What should happen to it after that person dies?
  • During the process of a resident data storing, managing and interacting with the smart devices, are technically done by the entity providing the smart home services. And, during the process, there should be the policies and agreement outlining data ownership, usage and retention period, including the residents retaining control over their personal information. Also, after a resident death, it includes that respecting the one's privacy preference and ensuring the secure deletion or anonymisation of their data in compliance with the applicable regulations and contractual obligations.

Comments

Popular posts from this blog

MIDI

Accessibility

Servo Motors