Protection of Private Information

JBRADDEN
JBradden5-2InformationTechnologyRiskAnalysisandCyberSecurityPolicyAssignmentPart2.docx

5-2 Information Technology Risk Analysis and Cyber Security Policy Assignment, Part 2

7

Information Technology Case: Twitter Data Breach

SOUTHERN NEW HAMPSHIRE UNIVERSITY

Student: James L. Bradden

Professor: Pamela Boyett

Date: 17 October 2020

5-2 Information Technology Risk Analysis and Cyber Security Policy Assignment, Part 2

1

Twitter Data Breach

With the current data breach in the Twitter organization, the company should implement a cybersecurity policy that describes how employees, board members, partners, consultants as well as other users access websites, internet resources, transfer information through the networks, and carry out responsible security practices. Security policies are important measures taken in protecting computer systems and information inside the system. The cybersecurity policy should first explain the overall security expectation, responsibilities, and different employees' roles in the organization, and then the policies should have a different section of cybersecurity such as the requirement for antivirus software and safe use of cloud services (Moody, Siponen & Pahnila, 2018). The main objective of implementing these cybersecurity policies is to ensure that the Twitter organization maintains confidentiality, availability, and integrity of their information to avoid a negative effect on their operations and professional overview. To achieve these security objectives, Twitter should establish a complete information security management system that covers all employees, activities, business technology, and functional and operational units within the organization. These policies would be applicable to all the staff members in the Twitter organization as well as third parties who have stake in the data and the assets applied to store and analyze that information.

Organizational Security Policy

The organizational security policy should begin with a network policy which will identify the rules for identifying computer access, authentication, and the defense of the organizations network. This would include such implementations as firewalls, antivirus, and anti-malware software. A policy outlining access control should be put into place to further limit access to only those that require it. Access control is a component of both physical and information security which grants access to organizational information based on authorization and authentication. This policy would limit unauthorized individuals from accessing information stored, computer systems, storage facilities, or any other computing resources within the organization. The implementation of two-factor authentication would be advised in order to maintain information accountability via confidentiality, availability, and integrity. Two-factor authentication relates to something you have and something you know. Having a key card and knowing the associated pin refers to two-factor authentication and further emphasizes access control and the encryption of data across other platforms. The access control policy would assist in providing a logical access process that requires an approval to organizational data in order to minimize exposure, which would keep the data confidential, and provide a means of tracking access (Yazdanmehr & Wang, 2016).

In order to protect human resource information from intentional or accidental unauthorized access or modification a human resource security policy should be implemented. To further prevent the disclosure and destruction of sensitive and possible confidential information access should be highly restricted (Broadcom, 2020). In its role as an employer Twitter has a moral obligation and legal responsibility to protect and limit access to such information. The organizational security policy document should also cover physical security, which covers the protection of information and information processing facilities from being disclosed allowing for theft by unauthorized individuals. This policy can be combined with the access control policy to further reduce the loss and damage of sensitive information in storage and processing facilities. By implementing this policy, all those who enter and leave secure areas will be logged. The use of security cameras will be used to monitor their actions as well.

Compliance

The Consumer Privacy Act of the United States of America seeks to ensure that the personal identity of online customers is kept as private so that crimes such as identity theft can be avoided at all costs. These laws have also been put in place to minimize security breaches that could lead to the loss of data within the platforms. Misuse of the client’s data is also prohibited by law. Generally, all the laws including state and federal are designed to work towards the protection of client information on all online platforms. The Federal Trade Commission Act has the authority to take action against commercial entities that fail to implement and maintain proper security measures required to protect company personnel data. With the proper management of an access control and human resource policy the risks associated with unauthorized access and handling of user data is greatly reduced.

The data breach was primarily due to employees not recognizing a phishing attack and not following the proper security protocols to prevent falling victim. There is a law that requires all applicants to carry out a training course on data security as a way of making sure that all the employees will comply with policies implemented in their places of work (Holt, 2018). Mandatory information assurance training would be required for all employees accessing the network. Those that do complete the training would lose access. Ensuring that this training is completed on a yearly basis would emphasize the fact that security is everyone’s responsibility while informing them of the different methods hackers use to gain access for malicious intent.

In the United States, more than forty-three states have implemented strict laws as the cyber threats continue to evolve and get more advanced due to the rapid advancement and innovation of new technologies, thus the need to make cybersecurity strategies a top priority. One of the laws enacted in Alabama requires that all entities must be licensed through the department insurance to create, implement, and maintain information security programs. Within the Twitter organization, there has been established several policies that ensure that employees maintain information security.

Risks and Vulnerabilities

In order to minimize risks and vulnerabilities a risk assessment should be done. In order for any organization to maintain the integrity of a network and its information the implementation of end-user training is a must. Making it mandatory for employees to conduct cyber security awareness training will inform them of what a potential cyber security breach looks like and the actions they should take to ensure information stays secured. Secondly, the network policy will ensure that all operating systems have been updated with the latest security patches and antirust updates. Minimal access to data and data facilities is managed through the implementation of a detailed access control policy. Every user having access to sensitive information only increases the risk of accidental or intended release or damage of information.

Network segmentation and segregation with the use of firewalls and trusted zones will reduce the impact of a network intrusion. With the increase craft of hackers directly targeting internal networks via the use of social engineering and spear-phishing, it is important for organizations to segregate sensitive information and segment the network. Having a data backup plan in place as part of the physical security policy will ensure that data is backed up, secure, encrypted, and stored at a secure off-site location. Lack of a proper backup plan will lead to a significant loss of information due to a cyber-attack or natural disaster while staying in compliance with certain government regulations.

Security Policy Sections

Moreover, Twitter should also implement an Email and social media use policy that limits the use of other social media services to reduce the risks involved in the improper use of Email and social media platforms (Milosevic, 2016). This policy would ensure that all the information sent through Email would be well encrypted to avoid external sources from gaining access to organizational email traffic. All email traffic should be digitally signed to ensure validity and encrypted to provide yet another level of security. All employees who have network access to email and social media platforms should be responsible for using computer resources in a lawful and ethical manner. Conducting yearly cyber security training along with having each employee sign a statement of information system use and acknowledgement of user responsibilities will ensure employee compliance and liability.

The data breach of 2020 should act as a guide to emphasize the need of training employees of the different social engineering strategies. Since then Twitter has started to implement its own training strategies geared towards informing its employees of the different strategies used to gather information for malicious use. The organization has also implemented consequences for those employees who fail to follow the organization's policies since it can lead to private information been accessed by outsiders.

5-2 Information Technology Risk Analysis and Cyber Security Policy Assignment, Part 2

6

Reference

Broadcom. (2020, JUly 1). CA TOP SECRET FOR Z/OS 16.0. Retrieved from Human Resource Security Policy: https://techdocs.broadcom.com/us/en/ca-mainframe-software/security/ca-top-secret-for-z-os/16-0/using/implementing-multilevel-security/case-study/human-resource-security-policy.html

Holt, T. J. (2018). Regulating cybercrime through law enforcement and industry mechanisms.

The ANNALS of the American Academy of Political and Social Science, 679(1), 140-157.

Milosevic, T. (2016). Social media companies' cyberbullying policies. International Journal of Communication, 10, 22.

Moody, G. D., Siponen, M., & Pahnila, S. (2018). Toward a unified model of information security policy compliance. MIS Quarterly, 42(1).

Yazdanmehr, A., & Wang, J. (2016). Employees' information security policy compliance: A norm activation perspective. Decision Support Systems, 92, 36-46.