This report proposes a framework for ethical guidelines for computer and information security research, based on the principles set forth in the Belmont Report, a seminal report for ethical research in the biomedical and behavioral sciences.

We describe how the three principles of the Belmont Report can be usefully applied in fields related to research about or involving information and communication technology. ICT research raises new issues resulting from interactions between humans and communications technologies.

We illustrate the application of these principles to information systems security research — a critical infrastructure priority with broad impact and demonstrated potential for widespread harm — although we expect the proposed framework to be relevant to other disciplines, including those targeted by the Belmont report but now operating in more complex and interconnected contexts.

We outline the scope and framework for this work, including a historical summary of the conceptual foundations for traditional human subjects research, and the landscape of ICT research stakeholders.

We propose standard methods to operationalize these principles in the domain of research involving information and communication technology: identification of stakeholders and informed consent; balancing risks and benefits; fairness and equity; and compliance, transparency and accountability, respectively.

Belmont report 1979 pdf

We also describe how these principles and applications can be supported by external oversight by ethical review boards, and internal self-evaluation tools such as Ethical Impact Assessment. The intent of this report is to help clarify how the characteristics of ICT raise new potential for harm and to show how a reinterpretation of ethical principles and their application can lay the groundwork for ethically defensible research. Keywords: data sharing, ethics, policy.

