Protection of Private Information
1
Running head: 7-2 Milestone Three: Recommendations and Global Considerations
8
7-2 Milestone Three: Recommendations and Global Considerations
Recommendations and Global Considerations
SOUTHERN NEW HAMPSHIRE UNIVERSITY
Student: James L. Bradden
Professor: Pamela Boyett
Date: 25 October 2020
Recommendations and Global Considerations
During the investigation of the Twitter attack, several things have come to light, such as having originated from a social engineering attack aimed at Twitter employees. This age old scam of phishing was given new life in this new age of social media. Phone spear phishing has become a disturbing trend as users risk exposing their personal data to malicious hackers. Once the attacker was able to get credentialed information they were able to use those credentials to gain access to user profiles. The attacker even managed to change the security settings of user names and post pictures of Twitter’s internal dashboards (Greenberg, 2020). The internal systems were probably not as maintained with the same level of rigor as the publicly facing systems as access should have been more restrictive. If the attacker had dev deeper into the internal systems, they could have exploited the vulnerability or utilized gathered credentials and began to do damage to the infrastructure rather than just manipulate user profiles ("Twitter Investigation Report," 2020).
Recommendations: Organizational Change
There could have been the implementation of cybersecurity tools that put a focus on cyber hygiene, actively monitoring the details about the firm and staff members that are publicly available and identifying approaches to mitigate that footprint, providing protection to the company and well as integrity and privacy to each individual.
The company should review how different platforms that it uses can create a pathway for attackers. There should be mandatory regular testing due to the outsourcing of most platforms, and third parties with access to the internal systems. I would recommend the implementation of a robust cybersecurity framework that is sufficient and adequate in order to maintain a gold standard. Third-party threats are exactly where vendor risk management is crucial. It is key to comprehend what the company’s exposure is according to the level of access a third-party has to your systems, users, data, and clients. The company can also implement a vendor risk program that provides a dual assessment of its vendors, real-time threat assessments as well as managed detection response solutions to proactively track and reduce threats to its environment on a daily basis for the proper running of the business. Lastly, I would recommend the beefing up of multi-factor authentication where uses have to provide multiple pieces of evidence as authentication before being permitted to log into the system.
Recommendations: Ethical Guidelines
Due to the large volumes of data that people and organizations are producing today, many of us are not fully aware of how exposed our property and lives are, or can be with poor cybersecurity practices. Some of the most common cyber-attacks regarding privacy are inclusive of identity theft. Personal identification details are subjected to theft and can be utilized to impersonate victims. Such risks to privacy are increased by the development of a chaotic global data ecosystem which provides majority of the people with minute ability to individually curate, correct, delete, or influence the release or storage of their private information. In networked areas, confidential data can hardly stay limited within the digital platform where it was initially shared or formed. In this context, cybersecurity professionals should acknowledge the public trust to provide a critical line of defense against organizational and personal privacy harms rather than the actual owners of the sensitive information. The company should realize that poor cybersecurity practices can be both ineffective and unethical, and as they can negligently expose Twitter users to theft and loss of data. The company should implement and follow ethical guidelines to make it harder for hackers to accomplish their goals.
Enterprise-wide risk assessment which is quite complex for the organization to strike a balance between trusting its staff, giving them access to accomplish the company’s mission, and safeguarding itself from the same staff. It is essential for the company to use risk management principles as a means of protection from outsiders and insiders. The company should implement enterprise-wide view of information security by identifying its major assets and then coming up with a risk management strategy.
Training of employees on security awareness and running background checks on them should be a standard of any organization. It is important to instill a culture of security awareness in order for all staff to comprehend the need for procedures, policies, and technical controls and the reasons why they must be enforced as well as the consequences for any infractions. All should be aware of these security policies and how to report policy violations. They should also take courses on preventing phishing and comprehending privacy. There should be forced strong password and account management policies. Any compromise of the company’s computer accounts can create an opportunity for insiders to circumvent automated and manual mechanisms in place to cause insider attacks. This should include placing stricter passwords requirements on users at higher risk, such as campaigns, politicians, and political journalists. The separation of duties and least privilege should be enforced through authorizing access to only those resources required to do their tasks. When major functions are divided among staff, there is a high chance that one employee could commit sabotage with the help of another. Due to the ongoing corona pandemic, there is a likelihood that the attack was fueled by the fact that some employees worked remotely. This creates a need for a layered defense against attacks done remotely. When staff are properly trained it adds another layer of protection. Audit logs should be maintained and employees are aware that their actions are being monitored and logged. It is, therefore, very essential to design and implement remote procedures and policies in a careful manner. Other ethical guidelines include the deployment of an AI solution to follow user behavior and risk factors. Such a machine learning tool can enable the spotting of red flags like the logging in of an employee from a different device or location, or time (Gomes, Reis & Alturas, 2020, June).
Recommendations: External Standards
The company should have implemented a better process for protecting against data exfiltration. Employee termination is a top reason for malicious attacks against an organization. It is crucial to conduct a review for all people leaving the organization to ensure that they are not taking any company data with them. Also, the implementation of cybersecurity standards may enhance the capabilities of preparing, protecting, responding, and recovering from cyberattacks.
With regard to the occurrence of a breach, Twitter should be very quick to identifying and handling such an occurrence. In this particular incident, I believe that the company’s response to the attack was a cause for distress. Its first tweet about the incident gave little to no details, and the tweet that followed two hours later only said what most users had discovered for themselves: the disabling of verified users to tweet or reset their passwords while the company worked to resolve its issues. I think that Twitter should share all details of the event as well as the response and recovery procedures in order to prevent future attacks with the public as an ethical standard (Elmas et al., 2020).
Global Considerations: International Compliance
The ISO/IEC 27001 is one of the best global standards, and its certification is very sought after, as it demonstrates that an organization can be entrusted with information since it has adequate controls in place to protect it. It provides the requirements for the creation, implementation, maintenance, and continual improvement of an information security management system. It is the latest and the only recognized certification standard for information and cybersecurity. This standard would have been very relevant to the Twitter case since such a breach indicates that the company did not have sufficient measures to prevent a hack and protect the personal information provided by its users. If the company had followed this standard to the latter, this entire incidence could have been avoided as well as any future events (Humphreys, 2016).
Global Considerations: Cultural Impacts
Twitter is one of the world's most essential communications systems, and among its users are critical accounts linked to political figures and emergency medical services. Twitter had been slow to invest in an early warning technology. The attack raised new concerns about Twitter's ability to keep the accounts of global leaders safe. Also, the attackers managed to compromise the accounts of some prominent tech billionaires such as Musk and Bill Gates. This shows that this incident could have wreaked havoc on the stock market as tweets from such people have a strong influence. Also, a temporary freeze of the verified Twitter accounts led to chaos on the platform, and it represented Twitter's inability to handle the balancing of equities. Some accounts conveying important information such as tornado warnings suddenly went dark, leaving some people unaware. Such an instance where an individual can take over an account of a global leader leaves many questions of the potential that these attackers have, such as slurring political views which could affect a nation. This attack was a successful attack on Twitter's security, where people communicate both privately via direct message service and publicly. Given the significance of social media platforms in communication on a global scale and the history of previous attacks, such incidents like the Twitter hack expose risks to the integrity and stability of elections, national security, and financial markets (Oxford Analytica).
Global Considerations: Global Technology Environment
In the past few years, there have been very few changes to the regulatory laws of how companies should handle personal information. The internet is global, and even though Twitter has its headquarters at San Francisco, California, the U.S. doesn’t translate to hacker’s access of network and data theft from the same location. Though the hackers were from the United States, the personal data that was stolen is destined for the Dark Web for purchase. Currently, there is no dedicated state or federal regulator empowered to make sure there are sufficient cybersecurity practices to prevent disinformation, fraud, and other systemic threats to social media giants. There should be some type of policy established with the Financial Stability Oversight Council (FSOC) to ensure that there are policies in place to ensure that essential social media firms are protecting their systems and associated data from attack that could potentially pose a threat to financial companies. Once designated, these companies should undergo enhanced regulatory stress tests to analyze their susceptibility data breaches. The Twitter hack properly shows the risk to society when systemically crucial institutions are left to regulate themselves. Protecting systemically critical social media against misuse is important to all users especially to users, such as voters, consumers, government leads, and industry ("Twitter Investigation Report", 2020).
References
Elmas, T., Overdorf, R., Özkalay, A. F., & Aberer, K. (2020). The Power of Deletions: Ephemeral Astroturfing Attacks on Twitter Trends. arXiv preprint arXiv:1910.07783.
Gomes, V., Reis, J., & Alturas, B. (2020, June). Social Engineering and the Dangers of Phishing. In 2020 15th Iberian Conference on Information Systems and Technologies (CISTI) (pp. 1-7). IEEE.
Greenberg, A. (2020, August 18). The Attack That Broke Twitter Is Hitting Dozens of Companies. Retrieved from Wired: https://www.wired.com/story/phone-spear-phishing-twitter-crime-wave/
Humphreys, E. (2016). Implementing the ISO/IEC 27001: 2013 ISMS Standard. Artech House.
Oxford Analytica. The Twitter attack will embolden calls for regulation. Emerald Expert Briefings, (oxan-es).
Twitter Investigation Report. Department of Financial Services. (2020). Retrieved 27 October 2020, from https://www.dfs.ny.gov/Twitter_Report.