Running Head: EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e 1
IT-549 Final project Submission
SNHU
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Contents
I Introduction ............................................................................................................................. 3
II The role of the key leaders within the Equifax organization ............................................ 5
III. Risk Assessment: Equifax .................................................................................................. 8
IV. Statements of Policy ........................................................................................................ 12
V. Conclusion: ......................................................................................................................... 16
VI. References ......................................................................................................................... 19
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
I Introduction
Equifax Inc. is a reputed business undertaking that specializes in data analytics
and technology. In the year 2017, cyber attackers had gained access into the system of
the business entity and compromised secretive data and information of around 143
million American consumers (Equifax Says Cyberattack May Have Affected 143 Million
in the U.S, 2019). They had compromised confidential details such as name, address,
birth date, driver’s license number and Social Security Number. The incident had gained
a lot of attention for all the wrong reasons. In fact, the cyber-attack on the business
entity was considered to be one of the largest risks relating to the personal and sensitive
information of the 21st century (Deanne, 2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an
insight into the importance of the confidentiality, integrity, and availability of
information. The incident which jolted the business organization arose as the business
was using an open-source framework known as Apache Struts for the purpose of
addressing the online disputes relating to its web application. It had a number of
loopholes which exposed its vulnerability to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place two
months prior to the disclosure of the vulnerability of the business entity. In case a
robust cybersecurity model was in place, such an unfateful cyber occurrence could have
been avoided by Equifax Inc. The business undertaking failed to upgrade its existing
systems which ultimately resulted in one of the most severe cyber-attacks in the history
of mankind (Deanne, 2019).
In order to avoid history from repeating itself, there is a need for Equifax Inc. to
learn from the mistakes and understand the significance of maintaining the
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
confidentiality, integrity, and availability of information. The creation and maintenance
of a robust and well-designed information assurance plan is beneficial to safeguard the
confidential data and information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was in
place to safeguard the privacy of its stakeholders including the customers. Even though
the business undertaking was one of the most reputed customer credit reporting agencies,
the cyber security complacency at the business organization was poor and obsolete. In
fact, the cyber-attack that took place could have been prevented only if the business
concern had in place an upgraded version of the security system (Solomon, 2019).
The business concern miserably failed to implement and execute some of the
basic security protocols like the file integrity monitoring technique and the network
segmentation practice. The focus on confidentiality, integrity and availability of
information was negligible due to which the cyber attackers were able to take advantage
of the poor security model of the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information
within the organization has revealed that the CIA triad was weak which allowed the
online attackers to infiltrate sensitive and confidential at relating to millions of people.
The digital certificate which allowed the company to monitor the encrypted network
traffic that flew through its environment had expired almost 19 months prior to the
security breach incident.
Current protocols and policies of the Equifax Inc. organization
The business undertaking believes that it is its primary responsibility to protect
and safeguard consumer reports. On the official website of the business, it has claimed
to protect the proprietary information including accounting information, subscriber code,
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
and all the other non-public business details. The business has, in fact, introduced a
number of procedures and policies that its clients need to abide by in order to access,
obtain or distribute the firm’s information (Exhibit A - Internet Security Requirements,
2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not clear
to what extent the procedure is followed by the concern (Fortune.com, 2019). In spite of
the heavy claims that the business has made about its cybersecurity approach, it has
been involved in a serious of obvious errors and it has failed to find any fixes for the
same.
Some of the potential barriers that hinder the implementation of a new
information assurance plan in the business undertaking include the absence of a strict
security protocol and the presence of a weak internal defense mechanism (Staff, 2019).
II The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure that
the security infrastructure is robust and up-to-date. In the case of the Equifax concern,
when the cyber attack took place, the CEO of the entity was Mr. Richard Smith. Soon
after the security breach incident had occurred, he was the third senior executive to have
retired from the business undertaking. The other members who had previously left the
organization soon after the cyber incident were Susan Mauldin and David Webb
(Equifax hack: two executives to leave company after breach, 2019). They were the top
security officer and the chief information officer respectively. The leaders resigned as it
was their responsibility to take care of the security environment of Equifax but they
failed to implement a robust security system. Due to their poor approach, the security
breach incident took place which compromised the confidential data and information of
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
almost 143 million American consumers (Equifax hack: two executives to leave
company after breach, 2019).
The core leadership members of Equifax had not been capable enough to
safeguard the online data and information pertaining to their customers and clients. So
new leaders were appointed where Mr. Paulino do Rego Barros, Jr served as the new
CEO and Mark Feidler was selected as the Non-executive Chairman. The main reason
for the change of leadership in the organization was due to the poor responsiveness of
the former leaders to strengthen the security model firm’s information (Equifax CEO
Richard Smith suddenly decides to ‘retire’, 2019). Richard Smith failed to design a full
proof security model for Equifax due to which a number of vulnerabilities of the entity
were exploited by online hackers. Similarly, Susan Mauldin and David Webb who were
holding vital leadership positions in the organizational context were not capable enough
to upgrade and strengthen the security system that was at par with the industry
standards.
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information
assurance must be taken into account by the leaders in the evolving organizational
context. In the case of the Equifax entity, the cyber breach exposed the catastrophic
mismanagement of the security infrastructure by its leaders (Equifax CEO Richard Smith
suddenly decides to ‘retire’, 2019). The leaders had failed to take an ethical and legal
stance while designing the security framework. This is evident from the fact that they
had failed to patch a well-known security loophole which is the main reasons why the
online hackers were able to gain access into the organizational system.
The main legal and ethical considerations that the new leaders of the entity took
after the cyber attack include the introduction of the TrustedID Premier services. This
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
new technique will basically enable the customers to the business entity to determine
whether they have been adversely affected by an incident or not. In case robust ethical
and legal elements are not taken into account by organizations, adverse implications can
be faced by the affected organization especially, the leaders (Rep. Correa Reiterates
Need For Federal Data Breach Laws, 2019). For instance, federal law has been designed
in California after the data breach incident which crippled the Equifax business entity.
Businesses must notify the Federal Bureau of Investigation (FBI), Federal Trade
Commission (FTC) and other agencies about the data breach incident. e e
The key components of information assurance
In order to establish a robust security system in the organizational context,
business undertakings need to have proper and updated security policies that revolve
around confidentiality, integrity, and availability of information. In the Equifax entity,
the security policy was not well designed. In fact, the business undertaking failed to
match the security model with its market growth (Bloomberg - Are you a robot?, 2019).
The organization did not have clear lines of authority due to which a number of gaps
existed in the security system. Similarly, the organization that specialized in data
analytics and technology failed to modernize its technology-based security model with
the evolving times and changing the technological landscape. As per reports, if the
business organization would have been able to take suitable actions against the
observable security loopholes prior to the cyber incident, the data breach accident could
have been totally prevented.
On the highly dynamic and unpredictable technological business setting, business
undertakings need to focus on the confidentiality aspect, integrity aspect and availability
aspect of technology. These key components of information assurance must be ingrained
so that a safe and secure It infrastructure can be created by a business entity.
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 8
III. Risk Assessment: Equifax
The term ‘risk assessment’ can be defined as the process of identifying hazards,
negative influences or risk factors are identified. These elements have the potential to
cause harm in a specific context such as a business organization. A proper risk
assessment process is necessary so that a business concern can effectively function in a
dynamic and uncertain environment (Risk Assessment, 2019).
In the information technology context, a wide range of risks and threats can arise
and have an adverse implication on the manner in which a firm functions. Thus there is
a need to do a thorough risk assessment and devise a suitable information assurance
plan. The risk assessment process acts as the core foundation which can help an entity
to identify the various sources of risks and uncertainties that have the ability to
jeopardize the sustainability of the business (National Research Council, 2007).
The main goals of the risk assessment process are as follows:
❖ Identify the risks and gaps and monitoring the performance against the
requirements.
❖ Identify and prioritize the IT-related risks to the business concern.
❖ Design an effective and robust IT inventory model that can strengthen the
Information Technology infrastructure of the business undertaking.
❖ Mitigate the identified risks that face the business undertaking by implementing
suitable plans (Monahan & Skeem, 2016).
The environment in which Equifax operates
The Equifax business is primarily involved in the data analytics and technology-
based processes. It enables its clients including business organizations and individuals to
make informed decisions. The customers of the business are enabled to connect with a
wide range of equipment so that they can connect to a network. All these aspects are
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 9
necessary so that the business undertaking can offer the best possible credit reference
and data intelligence services in the market (Corporate Social Responsibility | ABout
Equifax | Equifax UK, 2019).
The business undertaking understands that the environment in which it functions
plays a critical role to impact the ultimate service that is offered to its clients. The
current policy of Equifax stresses on the privacy aspects as well as the security aspects
so that the consumers can avail the offerings in a safe and secure environmental setting.
Due to the high level of uncertainty that exists on the IT platform, the business has
introduced an effective online privacy and Cookie policy which will keep the private
information of its clients in a safe manner. In order to secure the clients in the
unpredictable business environment, Equifax has introduced in place a number of
security and confidentiality procedures relating to the storage and the disclosure of the
customer information.
Treat Environment of Environment
The information technology environment in which a majority of the business
processes and activities of Equifax are conducted is highly dynamic and unpredictable in
nature. One of the core elements that can endanger the network of the organization is
the ‘bring your own device’ BYOD concept. According to an article by Sally Ewalt,
even though this feature can enhance the quality of service for the clients, it is
necessary for an organization like Equifax to take into account the data security aspects
(Bring Your Own Device - But Don't Endanger the Network - Equifax Insights Blog,
2019).
A wide range of security issues can arise that need to be addressed on priority to
make sure that the BYOD model does not hamper the security model of the
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 10
organization (Privacy & Cookie Policy | Equifax UK, 2019). The main issues that must
be addressed are as follows:
❖ The strong authentication process could be compromised by introducing an
outside device.
❖ Theft of the device with sensitive organizational information
❖ The issues relating to the overall control of the BYOD in the organizational
context.
Best approaches for implementing information assurance principles
The privacy policy of the Equifax organization does not exactly elaborate on the
specific IT security approaches that are implemented at various levels of the entity. But
in order to implement the information assurance principles in the organizational setting,
Equifax must get a detailed understanding of the specific requirements. The business
must carefully select the IT assets that would contain digital information relating to the
clients in a safe and secure manner (Schou & Hernandez, 2014).
The job description relating to the position of the security risk assessment analyst
in Equifax must be elaborately captured. It would enable Equifax to employ suitable
personnel to take care of the IT security infrastructure. There is the need to focus on the
environmental as well as the physical security control measures so that a holistic
information assurance model could be designed for Equifax. The backup and restoration
of the digital information need to be carefully planned so that the organization could
have proper control over the sensitive data and information relating to its clients and
customers.
Threats to and vulnerabilities of Equifax – Risk matrix
Since the Equifax business undertaking mainly deals with sensitive and
confidential data relating to its clients, it is extremely necessary to mitigate the dangers
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 11
that arise in the digital arena. The risk matrix that has been presented below captures
the threats to Equifax and the vulnerabilities of Equifax in the dynamic technological
environmental setting. The intention is to outline the threats and vulnerabilities that
could adversely impact the business. Similarly, suitable mitigation strategies have also
been presented that would help to mitigate the identified dangers.
Threats
Risk of impact
Mitigation strategy
Loss of data or
leakage of data
High
Equifax can make sure that all the sensitive and
confidential data and information relating to its
clients are securely encrypted. This method
would make sure that even if the data is
compromised by an unauthorized party, it cannot
be decoded.
Malware
High
The Equifax organization must focus on
establishing robust cybersecurity hygiene. In
order to do so, the business entity needs to
employ proper firewalls, antiviruses and malware
software in place. This holistic technique would
help to identify malware that could compromise
the security mode of the organization.
Phishing
High
Phishing awareness workshops and training must
be designed so that the employees of Equifax
could get a proper understanding of the security
threat. Such a mitigation strategy would enable
them to identify phishing emails that could
adversely affect the security system of the
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 12
business organization.
Source: (Security Think Tank: 10 control areas to mitigate against malware
attacks, 2019)
IV. Statements of Policy
Lately, a large number of business undertakings have fallen victims to cyber-
attacks. One of the most well-known cyber incidents that had jolted the business setting
involved the Equifax firm. A number of protocols have been recommended for the firm.
Similarly, various mitigating factors to the organization have been highlighted as well.
The main protocols that have been captured here are the Incident Response protocols,
Disaster Response protocols, Access control protocols, and maintenance plan. The
intention is to design a robust information assurance plan so that such kinds of cyber
incidents can be managed and effectively tackled in the future by Equifax.
Incident Response protocols
The incident response protocol would enable the firm to properly respond and
react to such kinds of events in case they arise in the future. In order to do so, it is
extremely vital to involve organizational personnel in the security process. Equifax must
implement a functional incident response protocol so that the employees will be
empowered to respond to such an event. It would also allow them to take the necessary
steps to minimize the extent of the damage (Incident Response Protocol: Information
Technology - Northwestern University, 2019).
Some of the key stages that are involved in the incident response protocol
include the preparation by the response team, the identification of the environment, the
containment of the damage, the eradication of the threat from the system, recovery and
learning lessons from the incident (Response, 2019).
Justification of the Incident Response protocols
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 13
The protocol is necessary as it can help an organization to be ready to face a
cyber threat. Today, such threats can arise before any firm. The protocol will make sure
that the firm and its employees know the steps that they need to take so that they can
tactfully respond to the situation and control the damage. e e
Disaster Response protocols
The business undertakings that work in the global context such as Equifax must
devise suitable disaster response protocols. These protocols will primarily help to devise
a coordinated plan across the various business units which will help to face the danger
in the cyber setting. Equifax conducts its data analytics and technology function in
almost 24 nations (Myers, 2019).
Some of the main elements that can be introduced by Equifax in the Disaster
Response protocol include segregating the authority among professionals to close a site.
Similarly, all the security criteria must be clearly defined so that the leaders can act in
an independent manner. The firm must make sure that there exists no ambiguity while
distributing responsibilities among the organizational personnel of Equifax. In various
locations in which Equifax functions, it must implement streamlined and uniform
disaster response protocols. It would enable the firm to respond in an integrated manner
to tackle vulnerabilities in the cyber setting.
Justification of the Disaster Response protocols
The relevance of proper disaster response protocol would be extremely vital for
the Equifax concern. This element of the security policy would make sure that all the
individuals are aware of their exact roles and responsibilities when a threat in the cyber
setting arises. It would enable them to get a detailed insight into various angles from
where the threat could loom such as the attack on cloud services, mobile device attack,
and ghostware attack (Emergency Management for Cyber Attacks, 2019).
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 14
Access control protocols
Equifax would have to establish a number of access control protocols on its
policy so that specific individuals would have the authority to have access to certain
areas of the IT ecosystem. This protocol would ensure that professionals would be able
to meet certain criteria before they gain access to the system. This control mechanism
would enable the business to introduce innovative elements such as PIN, fingerprints
identification model or iris identification model.
The access control protocol of Equifax must be developed so that the firm could
be well equipped to defend itself from internal threats as well as external threats. The
protocol would facilitate the business concern to involve the appropriate team members
in the attack mitigation plans (my Social Security | Social Security Administration,
2019). A vital practice that the business undertaking must keep in mind relates to the
regular drafting, implementing and upgrading of the cybersecurity plan. Such an
approach would play an extremely critical role to prepare the firm to face uncertain
cyber events.
Justification of the access control protocols
Equifax needs to introduce the access control protocols in the security policy as
it would strengthen its security model in the uncertain cyber setting. These protocols
would safeguard the firm from internal threats as well as external risks. It would make
sure that power to have access to certain sensitive IT areas is in the hands of a few
individuals. Such an approach could minimize the vulnerability of the business in the
dynamic cyber setting.
Recommendation for maintaining the information assurance plan
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 15
In order to maintain the robust information assurance plan, Equifax must make
sure that the appropriate policies, practices, standards, and guidelines are always
followed by the organizational personnel.
The policies and security component must be matched with the firm’s risk
profile. A robust risk assessment model must be designed comprising of implementation,
monitoring, testing, and reporting elements. It would help to maintain the information
assurance plan of Equifax firm. e
In addition to the firm’s information security policy, Equifax must also follow
the security standards that are applicable at the industry level. For example, in case the
firm deals with branded credit cards from the clients, it must make sure to follow the
Payment Card Industry Data Security Standard (PCI DSS).
Since the information security policies and protocols would act as the backbone
of Equifax’s information assurance plan. It is necessary to follow the recommendations
so that the maintenance of the assurance plan could be possible (How to Develop &
Maintain Information Security Policies & Procedures, 2019).
Justification of the maintainable plan
The maintenance plan has been designed to make sure that the information
assurance plan of Equifax would play a vital role and defend the firm and its
Information Technology ecosystem in the unpredictable cyber setting. By properly
following the security model, the vulnerability of the firm could be controlled in a better
manner. The proper maintenance of the assurance plan by the business undertaking
would play a vital role to strengthen its stance against cyber attackers and hackers who
could exploit the vulnerabilities of the business concern. The proper maintenance of the
information assurance plan would help the firm to know the current status of the
security system. Thus it could strengthen, upgrade and maintain the quality of the
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 16
information assurance plan. In the unpredictable cyber setting, the role of the assurance
plan would be indispensable in nature for Equifax. It would help the business
undertaking to prevent similar kind of attack that had previously affected its brand
reputation and crippled its business activities.
V. Conclusion:
Need for information assurance plan:
Information assurance is the process of ensuring appropriate management of
specific data and risks pertaining to them in various aspects of application usage,
transmission, processing and storage. Information assurance is ensured by taking care of
different aspects such as integrity, confidentiality, availability, authenticity and non-
repudiation. The importance of information assurance plan is clearly observed in the
necessity for safeguarding user data in transit stages as well as with storage. Therefore,
information assurance is accounted as a significant component of data security because
business processes and transactions are prominently associated with digital management
practices.
Equifax has experienced considerable issues in information security due to the
hacking attack on its database which compromised many crucial details of consumers
such as name, birth date, social security number, driver’s license number and address.
This served as the primary background for reflecting on the need for a proper
information assurance plan for Equifax. From the basic viewpoint, Equifax is legally as
well as ethically obliged to safeguard user information with appropriate security
measures in place for digital information as well as physical information. It can also be
pointed out that information assurance not only deals with preventing external attacks on
the information systems of Equifax but also putting measures in place to ensure
recovery of the compromised information.
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 17
An outline of the legal and ethical responsibilities of Equifax for information
security could provide a reliable impression of the need for an information assurance
plan for the organization. In terms of legal responsibilities, the organization has to
comply with the federal law in California that clearly states the need to report
immediately to the Federal Bureau of Investigation (FBI) and the Federal Trade
Commission (FTC) as well as other agencies about the incident of data breach. The
organization has also made claims in its official business description about protecting
confidential information related to clients and customers through encrypting the
information. This points out towards the ethical responsibility of Equifax to invest
maximum efforts in protecting customer information. Another ethical responsibility that
can be identified in context of information assurance plan of Equifax is to monitor the
BYOD (Bring Your Own Device) use in organizational context for preventing any
information leaks. The TrustedID Premier services introduced by Equifax in the
aftermath of attacks on its information systems can be accounted as a formidable
component in the information assurance plan of Equifax as it can let customers know if
their information has been compromised or not. This provides a certain level of
autonomy to the clients for safeguarding the confidentiality, integrity and availability of
their information. Hence, Equifax has brought customers in the scope of its information
assurance measures that can help it in safeguarding its ethical obligations for information
security.
Key elements of information assurance plan:
The key stakeholders that have to be taken into consideration for the information
assurance plan of Equifax include the CEO, Chief Information Officer, Chief
Technology Officer and Chief Security Officer alongside employees, customers and
agencies such as the Federal Bureau of Investigation (FBI). Each of these stakeholders
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 18
has a different role in safeguarding the elements of confidentiality, integrity and
availability (CIA triad) of information at Equifax. Confidentiality refers to the protection
of access to information and this can be the responsibility of the Chief Information
Officer and the Chief Technology Officer. They are responsible for designing the
information security framework for the organization with appropriate policies and
procedures in place for ensuring that unauthorized agents are not able to access sensitive
information.
Employees as well as customers can also be held responsible for confidentiality
as they should not engage in disclosure of information access methods to external
agents. For examples, employees practicing the BYOD model should not allow external
agents to access their device and customers should protect their login id and details
from disclosure.
Integrity of the data is under the responsibility of the CEO, CIO and CTO as
they have to employ the necessary policies for establishing data accessing privileges and
the necessary penalties for violations thereby preventing any sort of unauthorized
modification in the information at Equifax. The CEO, CTO and CIO are also answerable
for availability element of information as they have to make sure of recovery systems
that can bring back the compromised information for use by clients. Hence, a clear
estimate of the need for information assurance plan for Equifax as well as the outline of
responsible stakeholders for different aspects of information assurance was able to
provide a conclusion to the design of a functional information plan highlighted in this
assessment. e e e e e e
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 19
VI. References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Bring Your Own Device - But Don't Endanger the Network - Equifax Insights Blog.
(2019). Retrieved from https://insight.equifax.com/bring-your-own-device-but-dont-
endanger-the-network/
Corporate Social Responsibility | ABout Equifax | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/about-equifax/corporate-social-responsibility/en_gb/
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to Protect
Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-happened-
protect/
Emergency Management for Cyber Attacks. (2019). Retrieved from
https://safetymanagement.eku.edu/blog/emergency-management-for-cyber-attacks/
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019). Retrieved
from https://www.nytimes.com/2017/09/07/business/equifax-cyberattack.html
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-
one-year-anniversary/
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 20
How to Prepare For and Respond To A Cyber Attack: Have A Disaster Recovery Plan |
OlenderFeldman LLP. (2019). Retrieved from https://www.olenderfeldman.com/how-
to-prepare-for-and-respond-to-a-cyber-attack-have-a-disaster-recovery-plan/
How to Develop & Maintain Information Security Policies & Procedures. (2019).
Retrieved from https://www.bankinfosecurity.com/webinars/how-to-develop-maintain-
information-security-policies-procedures-w-135
Incident Response Protocol: Information Technology - Northwestern University. (2019).
Retrieved from https://www.it.northwestern.edu/policies/incident.html
Monahan, J., & Skeem, J. L. (2016). Risk assessment in criminal sentencing. Annual
review of clinical psychology, 12, 489-513.
Myers, L. (2019). How many people outside the US are affected by the Equifax breach?
| WeLiveSecurity. Retrieved from https://www.welivesecurity.com/2017/09/15/many-
people-outside-u-s-affected-equifax-breach/
My Social Security | Social Security Administration. (2019). Retrieved from
https://www.ssa.gov/myaccount/
National Research Council. (2007). Scientific review of the proposed risk assessment
bulletin from the Office of Management and Budget. National Academies Press.
Privacy & Cookie Policy | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/About-us/Privacy_policy.html
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348
Risk Assessment. (2019). Retrieved from
https://www.ccohs.ca/oshanswers/hsprograms/risk_assessment.html
EQUIFAX CYBER ATTACK e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 21
Response, T. (2019). The Six Stages of Incident Response. Retrieved from
https://www.cso.com.au/article/600455/six-stages-incident-response/
Schou, C., & Hernandez, S. (2014). Information Assurance handbook: Effective
computer security and risk management strategies. McGraw-Hill Education Group.
Security Think Tank: 10 control areas to mitigate against malware attacks. (2019).
Retrieved from https://www.computerweekly.com/opinion/Security-Think-Tank-10-
control-areas-to-mitigate-against-malware-attacks
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames
‘culture of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae.
Retrieved from https://thecyberwire.com/articles/the-equifax-breach-consequences-
implications-and-sequelae.html