WGU C841 IHP4 TASK 1: LEGAL ANALYSIS ACCURATE AND
VERIFIED | 2026 UPDATE
Western Governors University
Legal Issues in Information Security
C841
Austen Garcia
IHP4 Task 1: Legal Analysis
, IHP4 Task 1: Legal Analysis
A1. CFAA and ECPA
A specific instance where information was accessed by an unauthorized user happened when the
BI Unit gained access to other groups and units within TechFite outside its own division using dummy
accounts. This instance directly violates the CFAA.
A specific instance of unauthorized access, use, disclosure, or interception of electronic
communications happens when evidence was found on the hard drive indicates recent penetration
utilizing the Metasploit Tool to gain access to and scan into ip addresses for several internet based
companies. This instance directly violates the ECPA.
A2. Three Laws
I noticed, in regards to negligence, that while there has been a great job on protecting against
the company’s external threats. There seems to be a lack of internal oversight as far as actual
documentation goes, there is nothing that discusses specific user account audits, escalation of privilege,
DLP, and surveillance. With little to no documentation, and the finding of the Metasploit tool, it has
allowed Sarah Miller to have plenty of time to scan and penetrate other companies’ networks without
proper authorization, therefore violating the ECPA.
The BI Unit has no separation of duties, a normal user has full administrative rights. The unit,
specifically Nadia Johnson, has never done any audits on user accounts. A request was made from Carl
Jaspers to create two accounts for employees who had not worked at the company for over two years.
Saying that, the accounts have been in constant use. The emails associated with the accounts are in
communication with parties that are not clients with TechFite. These accounts were accessed without
proper authorization, therefore breaking the CFAA.
With the company having no internal oversight, and no discussions of auditing user accounts and
no segregation of IT administration, allowed what looks like to be the creation of fake companies in
VERIFIED | 2026 UPDATE
Western Governors University
Legal Issues in Information Security
C841
Austen Garcia
IHP4 Task 1: Legal Analysis
, IHP4 Task 1: Legal Analysis
A1. CFAA and ECPA
A specific instance where information was accessed by an unauthorized user happened when the
BI Unit gained access to other groups and units within TechFite outside its own division using dummy
accounts. This instance directly violates the CFAA.
A specific instance of unauthorized access, use, disclosure, or interception of electronic
communications happens when evidence was found on the hard drive indicates recent penetration
utilizing the Metasploit Tool to gain access to and scan into ip addresses for several internet based
companies. This instance directly violates the ECPA.
A2. Three Laws
I noticed, in regards to negligence, that while there has been a great job on protecting against
the company’s external threats. There seems to be a lack of internal oversight as far as actual
documentation goes, there is nothing that discusses specific user account audits, escalation of privilege,
DLP, and surveillance. With little to no documentation, and the finding of the Metasploit tool, it has
allowed Sarah Miller to have plenty of time to scan and penetrate other companies’ networks without
proper authorization, therefore violating the ECPA.
The BI Unit has no separation of duties, a normal user has full administrative rights. The unit,
specifically Nadia Johnson, has never done any audits on user accounts. A request was made from Carl
Jaspers to create two accounts for employees who had not worked at the company for over two years.
Saying that, the accounts have been in constant use. The emails associated with the accounts are in
communication with parties that are not clients with TechFite. These accounts were accessed without
proper authorization, therefore breaking the CFAA.
With the company having no internal oversight, and no discussions of auditing user accounts and
no segregation of IT administration, allowed what looks like to be the creation of fake companies in