homework
It is said that a patch was not applied to the Apache Struts and that vulnerability allowed the hackers to break in. In addition, the breach occurred between May and July of 2017, but was not reported to the public until September after Equifax had hired Mandiant to do an internal investigation of what had happened.
Also three Equifax executives sold off almost US $1.8 Million of their personal shares a month prior to the public disclosures.
Equifax set up a website for people to use https://www.equifaxsecurity2017.com which later was classified as insecure and built almost like a phishing website.
Using what we have learned in this class, write a 2 to 3 page paper that addresses:
· What policies and procedures appear to have been lacking at Equifax?
· Do any of the policies and procedures address what the executives are accused of doing?
· Why did they wait so long to inform the public? Legally what are they required to do?
· How could this have been avoided?
State your premise and supporting arguments, etc. clearly.
Note that I will take off up to 10% of the grade for poor grammar and misspellings. So be sure to run grammar and spell check
Resources:
Giant Equifax Data Breach, http://money.cnn.com/2017/09/07/technology/business/equifax-data-breach/index.html
https://www.nytimes.com/2017/10/03/business/equifax-congress-data-breach.html
https://en.wikipedia.org/wiki/Equifax