A cyber-security researcher, Ryan McAllister, discovers a vulnerability in the software used by a UK hospital trust's patient record system. Without permission, he accesses a live test copy of the system to confirm the vulnerability is real, then emails the hospital IT department describing the flaw. Two months later, having received no response, he publishes full technical details of the vulnerability, including working exploit code, on his personal blog. A criminal group then uses this exploit to access and copy 50,000 patients' medical records, which are later found for sale on the dark web.
(a)For each of the following actions, identify whether Ryan McAllister could be prosecuted under the Computer Misuse Act 1990, and if so, under which section: (i) accessing the test copy of the system without permission; (ii) publishing the exploit code online.(4)
(b)Identify which piece of legislation is relevant to the hospital trust's own responsibilities after 50,000 patient records are stolen, and explain what the trust may be required to do as a result.(4)
(c)Evaluate whether the ethical practice of 'responsible disclosure' (privately reporting vulnerabilities and giving organisations time to fix them before publishing details) is an adequate solution to balancing the interests of security researchers, organisations and the public. Using this scenario to support your answer, discuss whether current UK legislation, such as the Computer Misuse Act 1990, adequately supports ethical security research.(9)
(Total for Question 12 is 17 marks)