Legal and Ethical Aspects of the Cyber Security Kill Chain
Cybersecurity professionals know that technical prowess alone isn’t enough – we must also navigate a maze of legal requirements and ethical expectations. The Cyber Kill Chain (CKC) framework, originally developed by Lockheed Martin to outline the stages of a cyberattack, provides a useful lens to examine where these legal and ethical issues arise.
This chapter expands on each phase of the CKC – Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives – highlighting the key legal implications and ethical considerations at every step.
We’ll also dive into global cybersecurity laws (such as GDPR, CCPA/CPRA, HIPAA, PIPL, LGPD, etc.), discuss hot topics such as “hacking back,” data privacy, duty of care, and proportionality, and learn from recent case studies (SolarWinds, MOVEit, and Colonial Pipeline). Throughout...