**Security ethics** are guidelines for making appropriate decisions as a security professional. Being ethical requires that security professionals remain *unbiased* and *maintain* the *security* and *confidentiality* of private data.
Having a strong sense of ethics can help you navigate your decisions as a cybersecurity professional so you’re able to mitigate threats posed by threat actors’ constantly evolving tactics and techniques.
### Ethical principles and methodologies
Because [[Counterattacks]] are generally disapproved of or illegal, the security realm has created frameworks and controls—such as the confidentiality, integrity, and availability ([[Foundational Security Model|CIA]]) triad—to address issues of confidentiality, privacy protections, and laws.
**[[Confidentiality]]** means that only authorised users can access specific assets or data. Confidentiality as it relates to professional ethics means that there needs to be a high level of respect for privacy to safeguard private assets and data.
**Privacy protection** means safeguarding personal information from unauthorized use. Personally identifiable information (*PII*) and sensitive personally identifiable information (*SPII*) are types of personal data that can cause people harm if they are stolen. PII data is any information used to infer an individual's identity, like their name and phone number. *SPII* data is a specific type of PII that falls under *stricter handling guidelines*, including **social security numbers** and **credit card numbers**. To effectively safeguard PII and SPII data, security professionals hold an ethical obligation to secure private information, identify security vulnerabilities, manage organisational risks, and align security with business goals.
**Laws** are rules that are recognised by a community and enforced by a governing entity. As a security professional, you will have an ethical obligation to protect your organization, its internal infrastructure, and the people involved with the organization. To do this:
- You must remain unbiased and conduct your work honestly, responsibly, and with the highest respect for the law.
- Be transparent and just, and rely on evidence.
- Ensure that you are consistently invested in the work you are doing, so you can appropriately and ethically address issues that arise.
- Stay informed and strive to advance your skills, so you can contribute to the betterment of the cyber landscape.