1 / 22100%
Running Head: EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz 1
IT-549 Final project Submission
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 2
Contents
I Introduction............................................................................................................................. 3
II The role of the key leaders within the Equifax organization ........................................ 5
III. Risk Assessment: Equifax ................................................................................................. 8
IV. Statements of Policy........................................................................................................ 12
V. Conclusion: ........................................................................................................................ 16
VI. References ......................................................................................................................... 19
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 3
I Introduction
Equifax Inc. is a reputed business undertaking that specializes in data analytics
and technology. In the year 2017, cyber attackers had gained access into the system
of the business entity and compromised secretive data and information of around 143
million American consumers (Equifax Says Cyberattack May Have Affected 143
Million in the U.S, 2019). They had compromised confidential details such as name,
address, birth date, driver’s license number and Social Security Number. The incident
had gained a lot of attention for all the wrong reasons. In fact, the cyber-attack on
the business entity was considered to be one of the largest risks relating to the
personal and sensitive information of the 21st century (Deanne, 2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an
insight into the importance of the confidentiality, integrity, and availability of
information. The incident which jolted the business organization arose as the business
was using an open-source framework known as Apache Struts for the purpose of
addressing the online disputes relating to its web application. It had a number of
loopholes which exposed its vulnerability to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place
two months prior to the disclosure of the vulnerability of the business entity. In case
a robust cybersecurity model was in place, such an unfateful cyber occurrence could
have been avoided by Equifax Inc. The business undertaking failed to upgrade its
existing systems which ultimately resulted in one of the most severe cyber-attacks in
the history of mankind (Deanne, 2019).
In order to avoid history from repeating itself, there is a need for Equifax Inc.
to learn from the mistakes and understand the significance of maintaining the
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 4
confidentiality, integrity, and availability of information. The creation and maintenance
of a robust and well-designed information assurance plan is beneficial to safeguard
the confidential data and information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was
in place to safeguard the privacy of its stakeholders including the customers. Even
though the business undertaking was one of the most reputed customer credit
reporting agencies, the cyber security complacency at the business organization was
poor and obsolete. In fact, the cyber-attack that took place could have been prevented
only if the business concern had in place an upgraded version of the security system
(Solomon, 2019).
The business concern miserably failed to implement and execute some of the
basic security protocols like the file integrity monitoring technique and the network
segmentation practice. The focus on confidentiality, integrity and availability of
information was negligible due to which the cyber attackers were able to take
advantage of the poor security model of the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information
within the organization has revealed that the CIA triad was weak which allowed the
online attackers to infiltrate sensitive and confidential at relating to millions of
people. The digital certificate which allowed the company to monitor the encrypted
network traffic that flew through its environment had expired almost 19 months prior
to the security breach incident.
Current protocols and policies of the Equifax Inc. organization
The business undertaking believes that it is its primary responsibility to protect
and safeguard consumer reports. On the official website of the business, it has
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 5
claimed to protect the proprietary information including accounting information,
subscriber code, and all the other non-public business details. The business has, in
fact, introduced a number of procedures and policies that its clients need to abide by
in order to access, obtain or distribute the firm’s information (Exhibit A - Internet
Security Requirements, 2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not
clear to what extent the procedure is followed by the concern (Fortune.com, 2019). In
spite of the heavy claims that the business has made about its cybersecurity approach,
it has been involved in a serious of obvious errors and it has failed to find any fixes
for the same.
Some of the potential barriers that hinder the implementation of a new
information assurance plan in the business undertaking include the absence of a strict
security protocol and the presence of a weak internal defense mechanism (Staff,
2019).
II The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure
that the security infrastructure is robust and up-to-date. In the case of the Equifax
concern, when the cyber attack took place, the CEO of the entity was Mr. Richard
Smith. Soon after the security breach incident had occurred, he was the third senior
executive to have retired from the business undertaking. The other members who had
previously left the organization soon after the cyber incident were Susan Mauldin and
David Webb (Equifax hack: two executives to leave company after breach, 2019).
They were the top security officer and the chief information officer respectively. The
leaders resigned as it was their responsibility to take care of the security environment
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 6
of Equifax but they failed to implement a robust security system. Due to their poor
approach, the security breach incident took place which compromised the confidential
data and information of almost 143 million American consumers (Equifax hack: two
executives to leave company after breach, 2019).
The core leadership members of Equifax had not been capable enough to
safeguard the online data and information pertaining to their customers and clients. So
new leaders were appointed where Mr. Paulino do Rego Barros, Jr served as the new
CEO and Mark Feidler was selected as the Non-executive Chairman. The main reason
for the change of leadership in the organization was due to the poor responsiveness
of the former leaders to strengthen the security model firm’s information (Equifax
CEO Richard Smith suddenly decides to ‘retire’, 2019). Richard Smith failed to
design a full proof security model for Equifax due to which a number of
vulnerabilities of the entity were exploited by online hackers. Similarly, Susan
Mauldin and David Webb who were holding vital leadership positions in the
organizational context were not capable enough to upgrade and strengthen the security
system that was at par with the industry standards.
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information
assurance must be taken into account by the leaders in the evolving organizational
context. In the case of the Equifax entity, the cyber breach exposed the catastrophic
mismanagement of the security infrastructure by its leaders (Equifax CEO Richard
Smith suddenly decides to ‘retire’, 2019). The leaders had failed to take an ethical
and legal stance while designing the security framework. This is evident from the fact
that they had failed to patch a well-known security loophole which is the main
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 7
reasons why the online hackers were able to gain access into the organizational
system.
The main legal and ethical considerations that the new leaders of the entity
took after the cyber attack include the introduction of the TrustedID Premier services.
This new technique will basically enable the customers to the business entity to
determine whether they have been adversely affected by an incident or not. In case
robust ethical and legal elements are not taken into account by organizations, adverse
implications can be faced by the affected organization especially, the leaders (Rep.
Correa Reiterates Need For Federal Data Breach Laws, 2019). For instance, federal
law has been designed in California after the data breach incident which crippled the
Equifax business entity. Businesses must notify the Federal Bureau of Investigation
(FBI), Federal Trade Commission (FTC) and other agencies about the data breach
incident. zz zz
The key components of information assurance
In order to establish a robust security system in the organizational context,
business undertakings need to have proper and updated security policies that revolve
around confidentiality, integrity, and availability of information. In the Equifax entity,
the security policy was not well designed. In fact, the business undertaking failed to
match the security model with its market growth (Bloomberg - Are you a robot?,
2019). The organization did not have clear lines of authority due to which a number
of gaps existed in the security system. Similarly, the organization that specialized in
data analytics and technology failed to modernize its technology-based security model
with the evolving times and changing the technological landscape. As per reports, if
the business organization would have been able to take suitable actions against the
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 8
observable security loopholes prior to the cyber incident, the data breach accident
could have been totally prevented.
On the highly dynamic and unpredictable technological business setting,
business undertakings need to focus on the confidentiality aspect, integrity aspect and
availability aspect of technology. These key components of information assurance
must be ingrained so that a safe and secure It infrastructure can be created by a
business entity.
III. Risk Assessment: Equifax
The term ‘risk assessment’ can be defined as the process of identifying
hazards, negative influences or risk factors are identified. These elements have the
potential to cause harm in a specific context such as a business organization. A
proper risk assessment process is necessary so that a business concern can effectively
function in a dynamic and uncertain environment (Risk Assessment, 2019).
In the information technology context, a wide range of risks and threats can
arise and have an adverse implication on the manner in which a firm functions. Thus
there is a need to do a thorough risk assessment and devise a suitable information
assurance plan. The risk assessment process acts as the core foundation which can
help an entity to identify the various sources of risks and uncertainties that have the
ability to jeopardize the sustainability of the business (National Research Council,
2007).
The main goals of the risk assessment process are as follows:
❖ Identify the risks and gaps and monitoring the performance against the
requirements.
❖ Identify and prioritize the IT-related risks to the business concern.
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 9
❖ Design an effective and robust IT inventory model that can strengthen the
Information Technology infrastructure of the business undertaking.
❖ Mitigate the identified risks that face the business undertaking by implementing
suitable plans (Monahan & Skeem, 2016).
The environment in which Equifax operates
The Equifax business is primarily involved in the data analytics and
technology-based processes. It enables its clients including business organizations and
individuals to make informed decisions. The customers of the business are enabled to
connect with a wide range of equipment so that they can connect to a network. All
these aspects are necessary so that the business undertaking can offer the best
possible credit reference and data intelligence services in the market (Corporate Social
Responsibility | ABout Equifax | Equifax UK, 2019).
The business undertaking understands that the environment in which it
functions plays a critical role to impact the ultimate service that is offered to its
clients. The current policy of Equifax stresses on the privacy aspects as well as the
security aspects so that the consumers can avail the offerings in a safe and secure
environmental setting. Due to the high level of uncertainty that exists on the IT
platform, the business has introduced an effective online privacy and Cookie policy
which will keep the private information of its clients in a safe manner. In order to
secure the clients in the unpredictable business environment, Equifax has introduced
in place a number of security and confidentiality procedures relating to the storage
and the disclosure of the customer information.
Treat Environment of Environment
The information technology environment in which a majority of the business
processes and activities of Equifax are conducted is highly dynamic and unpredictable
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 10
in nature. One of the core elements that can endanger the network of the
organization is the ‘bring your own device’ BYOD concept. According to an article
by Sally Ewalt, even though this feature can enhance the quality of service for the
clients, it is necessary for an organization like Equifax to take into account the data
security aspects (Bring Your Own Device - But Don't Endanger the Network -
Equifax Insights Blog, 2019).
A wide range of security issues can arise that need to be addressed on priority to
make sure that the BYOD model does not hamper the security model of the
organization (Privacy & Cookie Policy | Equifax UK, 2019). The main issues that
must be addressed are as follows:
❖ The strong authentication process could be compromised by introducing an
outside device.
❖ Theft of the device with sensitive organizational information
❖ The issues relating to the overall control of the BYOD in the organizational
context.
Best approaches for implementing information assurance principles
The privacy policy of the Equifax organization does not exactly elaborate on
the specific IT security approaches that are implemented at various levels of the
entity. But in order to implement the information assurance principles in the
organizational setting, Equifax must get a detailed understanding of the specific
requirements. The business must carefully select the IT assets that would contain
digital information relating to the clients in a safe and secure manner (Schou &
Hernandez, 2014).
The job description relating to the position of the security risk assessment
analyst in Equifax must be elaborately captured. It would enable Equifax to employ
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 11
suitable personnel to take care of the IT security infrastructure. There is the need to
focus on the environmental as well as the physical security control measures so that
a holistic information assurance model could be designed for Equifax. The backup
and restoration of the digital information need to be carefully planned so that the
organization could have proper control over the sensitive data and information relating
to its clients and customers.
Threats to and vulnerabilities of Equifax – Risk matrix
Since the Equifax business undertaking mainly deals with sensitive and
confidential data relating to its clients, it is extremely necessary to mitigate the
dangers that arise in the digital arena. The risk matrix that has been presented below
captures the threats to Equifax and the vulnerabilities of Equifax in the dynamic
technological environmental setting. The intention is to outline the threats and
vulnerabilities that could adversely impact the business. Similarly, suitable mitigation
strategies have also been presented that would help to mitigate the identified dangers.
Threats
Risk of impact
Mitigation strategy
Loss of data or
leakage of data
High
Equifax can make sure that all the sensitive
and confidential data and information relating
to its clients are securely encrypted. This
method would make sure that even if the data
is compromised by an unauthorized party, it
cannot be decoded.
Malware
High
The Equifax organization must focus on
establishing robust cybersecurity hygiene. In
order to do so, the business entity needs to
employ proper firewalls, antiviruses and
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 12
malware software in place. This holistic
technique would help to identify malware that
could compromise the security mode of the
organization.
Phishing
High
Phishing awareness workshops and training
must be designed so that the employees of
Equifax could get a proper understanding of
the security threat. Such a mitigation strategy
would enable them to identify phishing emails
that could adversely affect the security system
of the business organization.
Source: (Security Think Tank: 10 control areas to mitigate against malware
attacks, 2019)
IV. Statements of Policy
Lately, a large number of business undertakings have fallen victims to cyber-
attacks. One of the most well-known cyber incidents that had jolted the business
setting involved the Equifax firm. A number of protocols have been recommended for
the firm. Similarly, various mitigating factors to the organization have been
highlighted as well. The main protocols that have been captured here are the Incident
Response protocols, Disaster Response protocols, Access control protocols, and
maintenance plan. The intention is to design a robust information assurance plan so
that such kinds of cyber incidents can be managed and effectively tackled in the
future by Equifax.
Incident Response protocols
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 13
The incident response protocol would enable the firm to properly respond and
react to such kinds of events in case they arise in the future. In order to do so, it is
extremely vital to involve organizational personnel in the security process. Equifax
must implement a functional incident response protocol so that the employees will be
empowered to respond to such an event. It would also allow them to take the
necessary steps to minimize the extent of the damage (Incident Response Protocol:
Information Technology - Northwestern University, 2019).
Some of the key stages that are involved in the incident response protocol
include the preparation by the response team, the identification of the environment,
the containment of the damage, the eradication of the threat from the system,
recovery and learning lessons from the incident (Response, 2019).
Justification of the Incident Response protocols
The protocol is necessary as it can help an organization to be ready to face a
cyber threat. Today, such threats can arise before any firm. The protocol will make
sure that the firm and its employees know the steps that they need to take so that
they can tactfully respond to the situation and control the damage. zz zz
Disaster Response protocols
The business undertakings that work in the global context such as Equifax
must devise suitable disaster response protocols. These protocols will primarily help to
devise a coordinated plan across the various business units which will help to face
the danger in the cyber setting. Equifax conducts its data analytics and technology
function in almost 24 nations (Myers, 2019).
Some of the main elements that can be introduced by Equifax in the Disaster
Response protocol include segregating the authority among professionals to close a
site. Similarly, all the security criteria must be clearly defined so that the leaders can
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 14
act in an independent manner. The firm must make sure that there exists no
ambiguity while distributing responsibilities among the organizational personnel of
Equifax. In various locations in which Equifax functions, it must implement
streamlined and uniform disaster response protocols. It would enable the firm to
respond in an integrated manner to tackle vulnerabilities in the cyber setting.
Justification of the Disaster Response protocols
The relevance of proper disaster response protocol would be extremely vital
for the Equifax concern. This element of the security policy would make sure that all
the individuals are aware of their exact roles and responsibilities when a threat in the
cyber setting arises. It would enable them to get a detailed insight into various angles
from where the threat could loom such as the attack on cloud services, mobile device
attack, and ghostware attack (Emergency Management for Cyber Attacks, 2019).
Access control protocols
Equifax would have to establish a number of access control protocols on its
policy so that specific individuals would have the authority to have access to certain
areas of the IT ecosystem. This protocol would ensure that professionals would be
able to meet certain criteria before they gain access to the system. This control
mechanism would enable the business to introduce innovative elements such as PIN,
fingerprints identification model or iris identification model.
The access control protocol of Equifax must be developed so that the firm
could be well equipped to defend itself from internal threats as well as external
threats. The protocol would facilitate the business concern to involve the appropriate
team members in the attack mitigation plans (my Social Security | Social Security
Administration, 2019). A vital practice that the business undertaking must keep in
mind relates to the regular drafting, implementing and upgrading of the cybersecurity
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 15
plan. Such an approach would play an extremely critical role to prepare the firm to
face uncertain cyber events. zz
Justification of the access control protocols
Equifax needs to introduce the access control protocols in the security policy
as it would strengthen its security model in the uncertain cyber setting. These
protocols would safeguard the firm from internal threats as well as external risks. It
would make sure that power to have access to certain sensitive IT areas is in the
hands of a few individuals. Such an approach could minimize the vulnerability of the
business in the dynamic cyber setting.
Recommendation for maintaining the information assurance plan
In order to maintain the robust information assurance plan, Equifax must make
sure that the appropriate policies, practices, standards, and guidelines are always
followed by the organizational personnel.
The policies and security component must be matched with the firm’s risk
profile. A robust risk assessment model must be designed comprising of
implementation, monitoring, testing, and reporting elements. It would help to maintain
the information assurance plan of Equifax firm.
In addition to the firm’s information security policy, Equifax must also follow
the security standards that are applicable at the industry level. For example, in case
the firm deals with branded credit cards from the clients, it must make sure to
follow the Payment Card Industry Data Security Standard (PCI DSS).
Since the information security policies and protocols would act as the
backbone of Equifax’s information assurance plan. It is necessary to follow the
recommendations so that the maintenance of the assurance plan could be possible
(How to Develop & Maintain Information Security Policies & Procedures, 2019).
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 16
Justification of the maintainable plan
The maintenance plan has been designed to make sure that the information
assurance plan of Equifax would play a vital role and defend the firm and its
Information Technology ecosystem in the unpredictable cyber setting. By properly
following the security model, the vulnerability of the firm could be controlled in a
better manner. The proper maintenance of the assurance plan by the business
undertaking would play a vital role to strengthen its stance against cyber attackers
and hackers who could exploit the vulnerabilities of the business concern. The proper
maintenance of the information assurance plan would help the firm to know the
current status of the security system. Thus it could strengthen, upgrade and maintain
the quality of the information assurance plan. In the unpredictable cyber setting, the
role of the assurance plan would be indispensable in nature for Equifax. It would
help the business undertaking to prevent similar kind of attack that had previously
affected its brand reputation and crippled its business activities.
V. Conclusion:
Need for information assurance plan:
Information assurance is the process of ensuring appropriate management of
specific data and risks pertaining to them in various aspects of application usage,
transmission, processing and storage. Information assurance is ensured by taking care
of different aspects such as integrity, confidentiality, availability, authenticity and non-
repudiation. The importance of information assurance plan is clearly observed in the
necessity for safeguarding user data in transit stages as well as with storage.
Therefore, information assurance is accounted as a significant component of data
security because business processes and transactions are prominently associated with
digital management practices.
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 17
Equifax has experienced considerable issues in information security due to the
hacking attack on its database which compromised many crucial details of consumers
such as name, birth date, social security number, driver’s license number and address.
This served as the primary background for reflecting on the need for a proper
information assurance plan for Equifax. From the basic viewpoint, Equifax is legally
as well as ethically obliged to safeguard user information with appropriate security
measures in place for digital information as well as physical information. It can also
be pointed out that information assurance not only deals with preventing external
attacks on the information systems of Equifax but also putting measures in place to
ensure recovery of the compromised information.
An outline of the legal and ethical responsibilities of Equifax for information
security could provide a reliable impression of the need for an information assurance
plan for the organization. In terms of legal responsibilities, the organization has to
comply with the federal law in California that clearly states the need to report
immediately to the Federal Bureau of Investigation (FBI) and the Federal Trade
Commission (FTC) as well as other agencies about the incident of data breach. The
organization has also made claims in its official business description about protecting
confidential information related to clients and customers through encrypting the
information. This points out towards the ethical responsibility of Equifax to invest
maximum efforts in protecting customer information. Another ethical responsibility
that can be identified in context of information assurance plan of Equifax is to
monitor the BYOD (Bring Your Own Device) use in organizational context for
preventing any information leaks. The TrustedID Premier services introduced by
Equifax in the aftermath of attacks on its information systems can be accounted as a
formidable component in the information assurance plan of Equifax as it can let
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 18
customers know if their information has been compromised or not. This provides a
certain level of autonomy to the clients for safeguarding the confidentiality, integrity
and availability of their information. Hence, Equifax has brought customers in the
scope of its information assurance measures that can help it in safeguarding its
ethical obligations for information security.
Key elements of information assurance plan:
The key stakeholders that have to be taken into consideration for the
information assurance plan of Equifax include the CEO, Chief Information Officer,
Chief Technology Officer and Chief Security Officer alongside employees, customers
and agencies such as the Federal Bureau of Investigation (FBI). Each of these
stakeholders has a different role in safeguarding the elements of confidentiality,
integrity and availability (CIA triad) of information at Equifax. Confidentiality refers
to the protection of access to information and this can be the responsibility of the
Chief Information Officer and the Chief Technology Officer. They are responsible for
designing the information security framework for the organization with appropriate
policies and procedures in place for ensuring that unauthorized agents are not able to
access sensitive information.
Employees as well as customers can also be held responsible for
confidentiality as they should not engage in disclosure of information access methods
to external agents. For examples, employees practicing the BYOD model should not
allow external agents to access their device and customers should protect their login
id and details from disclosure.
Integrity of the data is under the responsibility of the CEO, CIO and CTO as
they have to employ the necessary policies for establishing data accessing privileges
and the necessary penalties for violations thereby preventing any sort of unauthorized
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 19
modification in the information at Equifax. The CEO, CTO and CIO are also
answerable for availability element of information as they have to make sure of
recovery systems that can bring back the compromised information for use by clients.
Hence, a clear estimate of the need for information assurance plan for Equifax as
well as the outline of responsible stakeholders for different aspects of information
assurance was able to provide a conclusion to the design of a functional information
plan highlighted in this assessment. zz zz zz zz zz zz
VI. References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Bring Your Own Device - But Don't Endanger the Network - Equifax Insights Blog.
(2019). Retrieved from https://insight.equifax.com/bring-your-own-device-but-dont-
endanger-the-network/
Corporate Social Responsibility | ABout Equifax | Equifax UK. (2019). Retrieved
from https://www.equifax.co.uk/about-equifax/corporate-social-responsibility/en_gb/
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to
Protect Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-
happened-protect/
Emergency Management for Cyber Attacks. (2019). Retrieved from
https://safetymanagement.eku.edu/blog/emergency-management-for-cyber-attacks/
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 20
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019).
Retrieved from https://www.nytimes.com/2017/09/07/business/equifax-
cyberattack.html
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-
one-year-anniversary/
How to Prepare For and Respond To A Cyber Attack: Have A Disaster Recovery
Plan | OlenderFeldman LLP. (2019). Retrieved from
https://www.olenderfeldman.com/how-to-prepare-for-and-respond-to-a-cyber-attack-
have-a-disaster-recovery-plan/
How to Develop & Maintain Information Security Policies & Procedures. (2019).
Retrieved from https://www.bankinfosecurity.com/webinars/how-to-develop-
maintain-information-security-policies-procedures-w-135
Incident Response Protocol: Information Technology - Northwestern University.
(2019). Retrieved from https://www.it.northwestern.edu/policies/incident.html
Monahan, J., & Skeem, J. L. (2016). Risk assessment in criminal sentencing. Annual
review of clinical psychology, 12, 489-513.
Myers, L. (2019). How many people outside the US are affected by the Equifax
breach? | WeLiveSecurity. Retrieved from
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 21
https://www.welivesecurity.com/2017/09/15/many-people-outside-u-s-affected-
equifax-breach/
My Social Security | Social Security Administration. (2019). Retrieved from
https://www.ssa.gov/myaccount/
National Research Council. (2007). Scientific review of the proposed risk assessment
bulletin from the Office of Management and Budget. National Academies Press.
Privacy & Cookie Policy | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/About-us/Privacy_policy.html
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348
Risk Assessment. (2019). Retrieved from
https://www.ccohs.ca/oshanswers/hsprograms/risk_assessment.html
Response, T. (2019). The Six Stages of Incident Response. Retrieved from
https://www.cso.com.au/article/600455/six-stages-incident-response/
Schou, C., & Hernandez, S. (2014). Information Assurance handbook: Effective
computer security and risk management strategies. McGraw-Hill Education Group.
Security Think Tank: 10 control areas to mitigate against malware attacks. (2019).
Retrieved from https://www.computerweekly.com/opinion/Security-Think-Tank-10-
control-areas-to-mitigate-against-malware-attacks
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames
‘culture of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
EQUIFAX CYBER ATTACK zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz z zz zz zz zz zz
zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz zz z zz zz zz zz zz zz zz zz zz zz 22
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae.
Retrieved from https://thecyberwire.com/articles/the-equifax-breach-consequences-
implications-and-sequelae.html
Students also viewed