1 / 20100%
Running Head: EQUIFAX CYBER ATTACK 1
IT-549 Final project Submission
Carlos Delapaz
SNHU
May 12 ,2019
EQUIFAX CYBER ATTACK 2
Contents
I Introduction..............................................................................................................................3
II The role of the key leaders within the Equifax organization..................................................5
III. Risk Assessment: Equifax....................................................................................................7
IV. Statements of Policy..........................................................................................................11
V. Conclusion:..........................................................................................................................15
VI. References..........................................................................................................................18
EQUIFAX CYBER ATTACK 3
I Introduction
Equifax Inc. is a reputed business undertaking that specializes in data analytics and
technology. In the year 2017, cyber attackers had gained access into the system of the
business entity and compromised secretive data and information of around 143 million
American consumers (Equifax Says Cyberattack May Have Affected 143 Million in the U.S,
2019). They had compromised confidential details such as name, address, birth date, driver’s
license number and Social Security Number. The incident had gained a lot of attention for all
the wrong reasons. In fact, the cyber-attack on the business entity was considered to be one of
the largest risks relating to the personal and sensitive information of the 21st century (Deanne,
2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an insight
into the importance of the confidentiality, integrity, and availability of information. The
incident which jolted the business organization arose as the business was using an open-
source framework known as Apache Struts for the purpose of addressing the online disputes
relating to its web application. It had a number of loopholes which exposed its vulnerability
to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place two
months prior to the disclosure of the vulnerability of the business entity. In case a robust
cybersecurity model was in place, such an unfateful cyber occurrence could have been
avoided by Equifax Inc. The business undertaking failed to upgrade its existing systems
which ultimately resulted in one of the most severe cyber-attacks in the history of mankind
(Deanne, 2019).
In order to avoid history from repeating itself, there is a need for Equifax Inc. to learn
from the mistakes and understand the significance of maintaining the confidentiality,
EQUIFAX CYBER ATTACK 4
integrity, and availability of information. The creation and maintenance of a robust and well-
designed information assurance plan is beneficial to safeguard the confidential data and
information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was in place
to safeguard the privacy of its stakeholders including the customers. Even though the
business undertaking was one of the most reputed customer credit reporting agencies, the
cyber security complacency at the business organization was poor and obsolete. In fact, the
cyber-attack that took place could have been prevented only if the business concern had in
place an upgraded version of the security system (Solomon, 2019).
The business concern miserably failed to implement and execute some of the basic
security protocols like the file integrity monitoring technique and the network segmentation
practice. The focus on confidentiality, integrity and availability of information was negligible
due to which the cyber attackers were able to take advantage of the poor security model of
the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information within
the organization has revealed that the CIA triad was weak which allowed the online attackers
to infiltrate sensitive and confidential at relating to millions of people. The digital certificate
which allowed the company to monitor the encrypted network traffic that flew through its
environment had expired almost 19 months prior to the security breach incident.
Current protocols and policies of the Equifax Inc. organization
The business undertaking believes that it is its primary responsibility to protect and
safeguard consumer reports. On the official website of the business, it has claimed to protect
the proprietary information including accounting information, subscriber code, and all the
other non-public business details. The business has, in fact, introduced a number of
EQUIFAX CYBER ATTACK 5
procedures and policies that its clients need to abide by in order to access, obtain or distribute
the firm’s information (Exhibit A - Internet Security Requirements, 2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not clear to
what extent the procedure is followed by the concern (Fortune.com, 2019). In spite of the
heavy claims that the business has made about its cybersecurity approach, it has been
involved in a serious of obvious errors and it has failed to find any fixes for the same.
Some of the potential barriers that hinder the implementation of a new information
assurance plan in the business undertaking include the absence of a strict security protocol
and the presence of a weak internal defense mechanism (Staff, 2019).
II The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure that the
security infrastructure is robust and up-to-date. In the case of the Equifax concern, when the
cyber attack took place, the CEO of the entity was Mr. Richard Smith. Soon after the security
breach incident had occurred, he was the third senior executive to have retired from the
business undertaking. The other members who had previously left the organization soon after
the cyber incident were Susan Mauldin and David Webb (Equifax hack: two executives to
leave company after breach, 2019). They were the top security officer and the chief
information officer respectively. The leaders resigned as it was their responsibility to take
care of the security environment of Equifax but they failed to implement a robust security
system. Due to their poor approach, the security breach incident took place which
compromised the confidential data and information of almost 143BmillionBAmerican
consumers (Equifax hack: two executives to leave company after breach, 2019).
The core leadership members of Equifax had not been capable enough to safeguard
the online data and information pertaining to their customers and clients. So new leaders were
EQUIFAX CYBER ATTACK 6
appointed where Mr. Paulino do Rego Barros, Jr served as the new CEO and Mark Feidler
was selected as the Non-executive Chairman. The main reason for the change of leadership in
the organization was due to the poor responsiveness of the former leaders to strengthen the
security model firm’s information (Equifax CEO Richard Smith suddenly decides to ‘retire’,
2019). Richard Smith failed to design a full proof security model for Equifax due to which a
number of vulnerabilities of the entity were exploited by online hackers. Similarly, Susan
Mauldin and David Webb who were holding vital leadership positions in the organizational
context were not capable enough to upgrade and strengthen the security system that was at
par with the industry standards.
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information assurance
must be taken into account by the leaders in the evolving organizational context. In the case
of the Equifax entity, the cyber breach exposed the catastrophic mismanagement of the
security infrastructure by its leaders (Equifax CEO Richard Smith suddenly decides to
‘retire’, 2019). The leaders had failed to take an ethical and legal stance while designing the
security framework. This is evident from the fact that they had failed to patch a well-known
security loophole which is the main reasons why the online hackers were able to gain access
into the organizational system.
The main legal and ethical considerations that the new leaders of the entity took after
the cyber attack include the introduction of the TrustedID Premier services. This new
technique will basically enable the customers to the business entity to determine whether they
have been adversely affected by an incident or not. In case robust ethical and legal elements
are not taken into account by organizations, adverse implications can be faced by the affected
organization especially, the leaders (Rep. Correa Reiterates Need For Federal Data Breach
Laws, 2019). For instance, federal law has been designed in California after the data breach
EQUIFAX CYBER ATTACK 7
incident which crippled the Equifax business entity. Businesses must notify the Federal
Bureau of Investigation (FBI), Federal Trade Commission (FTC) and other agencies about
the data breach incident.
The key components of information assurance
In order to establish a robust security system in the organizational context, business
undertakings need to have proper and updated security policies that revolve around
confidentiality, integrity, and availability of information. In the Equifax entity, the security
policy was not well designed. In fact, the business undertaking failed to match the security
model with its market growth (Bloomberg - Are you a robot?, 2019). The organization did
not have clear lines of authority due to which a number of gaps existed in the security system.
Similarly, the organization that specialized in dataBanalytics and technology failed to
modernize its technology-based security model with the evolving times and changing the
technological landscape. As per reports, if the business organization would have been able to
take suitable actions against the observable security loopholes prior to the cyber incident, the
data breach accident could have been totally prevented.
On the highly dynamic and unpredictable technological business setting, business
undertakings need to focus on the confidentiality aspect, integrity aspect and availability
aspect of technology. These key components of information assurance must be ingrained so
that a safe and secure It infrastructure can be created by a business entity.
III. Risk Assessment: Equifax
The term ‘risk assessment’ can be defined as the process of identifying hazards,
negative influences or risk factors are identified. These elements have the potential to cause
harm in a specific context such as a business organization. A proper risk assessment process
is necessary so that a business concern can effectively function in a dynamic and uncertain
environment (Risk Assessment, 2019).
EQUIFAX CYBER ATTACK 8
In the information technology context, a wide range of risks and threats can arise and
have an adverse implication on the manner in which a firm functions. Thus there is a need to
do a thorough risk assessment and devise a suitable information assurance plan. The risk
assessment process acts as the core foundation which can help an entity to identify the
various sources of risks and uncertainties that have the ability to jeopardize the sustainability
of the business (National Research Council, 2007).
The main goals of the risk assessment process are as follows:
Identify the risks and gaps and monitoring the performance against the requirements.
Identify and prioritize the IT-related risks to the business concern.
Design an effective and robust IT inventory model that can strengthen the Information
Technology infrastructure of the business undertaking.
Mitigate the identified risks that face the business undertaking by implementing
suitable plans (Monahan & Skeem, 2016).
The environment in which Equifax operates
The Equifax business is primarily involved in the data analytics and technology-based
processes. It enables its clients including business organizations and individuals to make
informed decisions. The customers of the business are enabled to connect with a wide range
of equipment so that they can connect to a network. All these aspects are necessary so that the
business undertaking can offer the best possible credit reference and data intelligence services
in the market (Corporate Social Responsibility | ABout Equifax | Equifax UK, 2019).
The business undertaking understands that the environment in which it functions
plays a critical role to impact the ultimate service that is offered to its clients. The current
policy of Equifax stresses on the privacy aspects as well as the security aspects so that the
consumers can avail the offerings in a safe and secure environmental setting. Due to the high
level of uncertainty that exists on the IT platform, the business has introduced an effective
EQUIFAX CYBER ATTACK 9
online privacy and Cookie policy which will keep the private information of its clients in a
safe manner. In order to secure the clients in the unpredictable business environment, Equifax
has introduced in place a number of security and confidentiality procedures relating to the
storage and the disclosure of the customer information.
Treat Environment of Environment
The information technology environment in which a majority of the business
processes and activities of Equifax are conducted is highly dynamic and unpredictable in
nature. One of the core elements that can endanger the network of the organization is the
‘bring your own device’ BYOD concept. According to an article by Sally Ewalt, even though
this feature can enhance the quality of service for the clients, it is necessary for an
organization like Equifax to take into account the data security aspects (Bring Your Own
Device - But Don't Endanger the Network - Equifax Insights Blog, 2019).
A wide range of security issues can arise that need to be addressed on priority to make
sure that the BYOD model does not hamper the security model of the organization (Privacy
& Cookie Policy | Equifax UK, 2019). The main issues that must be addressed are as follows:
The strong authentication process could be compromised by introducing an outside
device.
Theft of the device with sensitive organizational information
The issues relating to the overall control of the BYOD in the organizational context.
Best approaches for implementing information assurance principles
The privacy policy of the Equifax organization does not exactly elaborate on the
specific IT security approaches that are implemented at various levels of the entity. But in
order to implement the information assurance principles in the organizational setting, Equifax
must get a detailed understanding of the specific requirements. The business must carefully
EQUIFAX CYBER ATTACK
10
select the IT assets that would contain digital information relating to the clients in a safe and
secure manner (Schou & Hernandez, 2014).
The job description relating to the position of the security risk assessment analyst in
Equifax must be elaborately captured. It would enable Equifax to employ suitable personnel
to take care of the IT security infrastructure. There is the need to focus on the environmental
as well as the physical security control measures so that a holistic information assurance
model could be designed for Equifax. The backup and restoration of the digital information
need to be carefully planned so that the organization could have proper control over the
sensitive data and information relating to its clients and customers.
Threats to and vulnerabilities of Equifax – Risk matrix
Since the Equifax business undertaking mainly deals with sensitive and confidential
data relating to its clients, it is extremely necessary to mitigate the dangers that arise in the
digital arena. The risk matrix that has been presented below captures the threats to Equifax
and the vulnerabilities of Equifax in the dynamic technological environmental setting. The
intention is to outline the threats and vulnerabilities that could adversely impact the business.
Similarly, suitable mitigation strategies have also been presented that would help to mitigate
the identified dangers.
Threats Risk of impact Mitigation strategy
Loss of data or
leakage of data
High Equifax can make sure that all the sensitive and
confidential data and information relating to its
clients are securely encrypted. This method would
make sure that even if the data is compromised by
an unauthorized party, it cannot be decoded.
Malware High The Equifax organization must focus on
establishing robust cybersecurity hygiene. In order
EQUIFAX CYBER ATTACK
11
to do so, the business entity needs to employ proper
firewalls, antiviruses and malware software in
place. This holistic technique would help to identify
malware that could compromise the security mode
of the organization.
Phishing High Phishing awareness workshops and training must be
designed so that the employees of Equifax could get
a proper understanding of the security threat. Such a
mitigation strategy would enable them to identify
phishing emails that could adversely affect the
security system of the business organization.
Source: (Security Think Tank: 10 control areas to mitigate against malware attacks,
2019)
IV. Statements of Policy
Lately, a large number of business undertakings have fallen victims to cyber-attacks.
One of the most well-known cyber incidents that had jolted the business setting involved the
Equifax firm. A number of protocols have been recommended for the firm. Similarly, various
mitigating factors to the organization have been highlighted as well. The main protocols that
have been captured here are the Incident Response protocols, Disaster Response protocols,
Access control protocols, and maintenance plan. The intention is to design a robust
information assurance plan so that such kinds of cyber incidents can be managed and
effectively tackled in the future by Equifax.
Incident Response protocols
The incident response protocol would enable the firm to properly respond and react to
such kinds of events in case they arise in the future. In order to do so, it is extremely vital to
EQUIFAX CYBER ATTACK
12
involve organizational personnel in the security process. Equifax must implement a
functional incident response protocol so that the employees will be empowered to respond to
such an event. It would also allow them to take the necessary steps to minimize the extent of
the damage (Incident Response Protocol: Information Technology - Northwestern University,
2019).
Some of the key stages that are involved in the incident response protocol include the
preparation by the response team, the identification of the environment, the containment of
the damage, the eradication of the threat from the system, recovery and learning lessons from
the incident (Response, 2019).
Justification of the Incident Response protocols
The protocol is necessary as it can help an organization to be ready to face a cyber
threat. Today, such threats can arise before any firm. The protocol will make sure that the
firm and its employees know the steps that they need to take so that they can tactfully
respond to the situation and control the damage.
Disaster Response protocols
The business undertakings that work in the global context such as Equifax must
devise suitable disaster response protocols. These protocols will primarily help to devise a
coordinated plan across the various business units which will help to face the danger in the
cyber setting. Equifax conducts its data analytics and technology function in almost 24
nations (Myers, 2019).
Some of the main elements that can be introduced by Equifax in the Disaster
Response protocol include segregating the authority among professionals to close a site.
Similarly, all the security criteria must be clearly defined so that the leaders can act in an
independent manner. The firm must make sure that there exists no ambiguity while
distributing responsibilities among the organizational personnel of Equifax. In various
EQUIFAX CYBER ATTACK
13
locations in which Equifax functions, it must implement streamlined and uniform disaster
response protocols. It would enable the firm to respond in an integrated manner to tackle
vulnerabilities in the cyber setting.
Justification of the Disaster Response protocols
The relevance of proper disaster response protocol would be extremely vital for the
Equifax concern. This element of the security policy would make sure that all the individuals
are aware of their exact roles and responsibilities when a threat in the cyber setting arises. It
would enable them to get a detailed insight into various angles from where the threat could
loom such as the attack on cloud services, mobile device attack, and ghostware attack
(Emergency Management for Cyber Attacks, 2019).
Access control protocols
Equifax would have to establish a number of access control protocols on its policy so
that specific individuals would have the authority to have access to certain areas of the IT
ecosystem. This protocol would ensure that professionals would be able to meet certain
criteria before they gain access to the system. This control mechanism would enable the
business to introduce innovative elements such as PIN, fingerprints identification model or
iris identification model.
The access control protocol of Equifax must be developed so that the firm could be
well equipped to defend itself from internal threats as well as external threats. The protocol
would facilitate the business concern to involve the appropriate team members in the attack
mitigation plans (my Social Security | Social Security Administration, 2019). A vital practice
that the business undertaking must keep in mind relates to the regular drafting, implementing
and upgrading of the cybersecurity plan. Such an approach would play an extremely critical
role to prepare the firm to face uncertain cyber events.
Justification of the access control protocols
EQUIFAX CYBER ATTACK
14
Equifax needs to introduce the access control protocols in the security policy as it
would strengthen its security model in the uncertain cyber setting. These protocols would
safeguard the firm from internal threats as well as external risks. It would make sure that
power to have access to certain sensitive IT areas is in the hands of a few individuals. Such
an approach could minimize the vulnerability of the business in the dynamic cyber setting.
Recommendation for maintaining the information assurance plan
In order to maintain the robust information assurance plan, Equifax must make sure
that the appropriate policies, practices, standards, and guidelines are always followed by the
organizational personnel.
The policies and security component must be matched with the firm’s risk profile. A
robust risk assessment model must be designed comprising of implementation, monitoring,
testing, and reporting elements. It would help to maintain the information assurance plan of
Equifax firm.
In addition to the firm’s information security policy, Equifax must also follow the
security standards that are applicable at the industry level. For example, in case the firm deals
with branded credit cards from the clients, it must make sure to follow the Payment Card
Industry Data Security Standard (PCI DSS).B
Since the information security policies and protocols would act as the backbone of
Equifax’s information assurance plan. It is necessary to follow the recommendations so that
the maintenance of the assurance plan could be possible (How to Develop & Maintain
Information Security Policies & Procedures, 2019).
Justification of the maintainable plan
The maintenance plan has been designed to make sure that the information assurance
plan of Equifax would play a vital role and defend the firm and its Information Technology
ecosystem in the unpredictable cyber setting. By properly following the security model, the
EQUIFAX CYBER ATTACK
15
vulnerability of the firm could be controlled in a better manner. The proper maintenance of
the assurance plan by the business undertaking would play a vital role to strengthen its stance
against cyber attackers and hackers who could exploit the vulnerabilities of the business
concern. The proper maintenance of the information assurance plan would help the firm to
know the current status of the security system. Thus it could strengthen, upgrade and
maintain the quality of the information assurance plan. In the unpredictable cyber setting, the
role of the assurance plan would be indispensable in nature for Equifax. It would help the
business undertaking to prevent similar kind of attack that had previously affected its brand
reputation and crippled its business activities.
V. Conclusion:
Need for information assurance plan:
Information assurance is the process of ensuring appropriate management of specific
data and risks pertaining to them in various aspects of application usage, transmission,
processing and storage. Information assurance is ensured by taking care of different aspects
such as integrity, confidentiality, availability, authenticity and non-repudiation. The
importance of information assurance plan is clearly observed in the necessity for
safeguarding user data in transit stages as well as with storage. Therefore, information
assurance is accounted as a significant component of data security because business processes
and transactions are prominently associated with digital management practices.
Equifax has experienced considerable issues in information security due to the
hacking attack on its database which compromised many crucial details of consumers such as
name, birth date, social security number, driver’s license number and address. This served as
the primary background for reflecting on the need for a proper information assurance plan for
Equifax. From the basic viewpoint, Equifax is legally as well as ethically obliged to
safeguard user information with appropriate security measures in place for digital information
EQUIFAX CYBER ATTACK
16
as well as physical information. It can also be pointed out that information assurance not only
deals with preventing external attacks on the information systems of Equifax but also putting
measures in place to ensure recovery of the compromised information.
An outline of the legal and ethical responsibilities of Equifax for information security
could provide a reliable impression of the need for an information assurance plan for the
organization. In terms of legal responsibilities, the organization has to comply with the
federal law in California that clearly states the need to report immediately to the Federal
Bureau of Investigation (FBI) and the Federal Trade Commission (FTC) as well as other
agencies about the incident of data breach. The organization has also made claims in its
official business description about protecting confidential information related to clients and
customers through encrypting the information. This points out towards the ethical
responsibility of Equifax to invest maximum efforts in protecting customer information.
Another ethical responsibility that can be identified in context of information assurance plan
of Equifax is to monitor the BYOD (Bring Your Own Device) use in organizational context
for preventing any information leaks. The TrustedID Premier services introduced by Equifax
in the aftermath of attacks on its information systems can be accounted as a formidable
component in the information assurance plan of Equifax as it can let customers know if their
information has been compromised or not. This provides a certain level of autonomy to the
clients for safeguarding the confidentiality, integrity and availability of their information.
Hence, Equifax has brought customers in the scope of its information assurance measures that
can help it in safeguarding its ethical obligations for information security.
Key elements of information assurance plan:
The key stakeholders that have to be taken into consideration for the information
assurance plan of Equifax include the CEO, Chief Information Officer, Chief Technology
Officer and Chief Security Officer alongside employees, customers and agencies such as the
EQUIFAX CYBER ATTACK
17
Federal Bureau of Investigation (FBI). Each of these stakeholders has a different role in
safeguarding the elements of confidentiality, integrity and availability (CIA triad) of
information at Equifax. Confidentiality refers to the protection of access to information and
this can be the responsibility of the Chief Information Officer and the Chief Technology
Officer. They are responsible for designing the information security framework for the
organization with appropriate policies and procedures in place for ensuring that unauthorized
agents are not able to access sensitive information.
Employees as well as customers can also be held responsible for confidentiality as
they should not engage in disclosure of information access methods to external agents. For
examples, employees practicing the BYOD model should not allow external agents to access
their device and customers should protect their login id and details from disclosure.
Integrity of the data is under the responsibility of the CEO, CIO and CTO as they
have to employ the necessary policies for establishing data accessing privileges and the
necessary penalties for violations thereby preventing any sort of unauthorized modification in
the information at Equifax. The CEO, CTO and CIO are also answerable for availability
element of information as they have to make sure of recovery systems that can bring back the
compromised information for use by clients. Hence, a clear estimate of the need for
information assurance plan for Equifax as well as the outline of responsible stakeholders for
different aspects of information assurance was able to provide a conclusion to the design of a
functional information plan highlighted in this assessment.
EQUIFAX CYBER ATTACK
18
VI. References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Bring Your Own Device - But Don't Endanger the Network - Equifax Insights Blog. (2019).
Retrieved from https://insight.equifax.com/bring-your-own-device-but-dont-endanger-
the-network/
Corporate Social Responsibility | ABout Equifax | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/about-equifax/corporate-social-responsibility/en_gb/
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to Protect
Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-happened-protect/
Emergency Management for Cyber Attacks. (2019). Retrieved from
https://safetymanagement.eku.edu/blog/emergency-management-for-cyber-attacks/
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019). Retrieved from
https://www.nytimes.com/2017/09/07/business/equifax-cyberattack.html
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-one-
year-anniversary/
EQUIFAX CYBER ATTACK
19
How to Prepare For and Respond To A Cyber Attack: Have A Disaster Recovery Plan |
OlenderFeldman LLP. (2019). Retrieved from https://www.olenderfeldman.com/how-
to-prepare-for-and-respond-to-a-cyber-attack-have-a-disaster-recovery-plan/
How to Develop & Maintain Information Security Policies & Procedures. (2019). Retrieved
from https://www.bankinfosecurity.com/webinars/how-to-develop-maintain-
information-security-policies-procedures-w-135
Incident Response Protocol: Information Technology - Northwestern University. (2019).
Retrieved from https://www.it.northwestern.edu/policies/incident.html
Monahan, J., & Skeem, J. L. (2016). Risk assessment in criminal sentencing.BAnnual review
of clinical psychology,B12, 489-513.
Myers, L. (2019). How many people outside the US are affected by the Equifax breach? |
WeLiveSecurity. Retrieved from https://www.welivesecurity.com/2017/09/15/many-
people-outside-u-s-affected-equifax-breach/
My Social Security | Social Security Administration. (2019). Retrieved from
https://www.ssa.gov/myaccount/
National Research Council. (2007).BScientific review of the proposed risk assessment bulletin
from the Office of Management and Budget. National Academies Press.
Privacy & Cookie Policy | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/About-us/Privacy_policy.html
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348
Risk Assessment. (2019). Retrieved from
https://www.ccohs.ca/oshanswers/hsprograms/risk_assessment.html
EQUIFAX CYBER ATTACK
20
Response, T. (2019). The Six Stages of Incident Response. Retrieved from
https://www.cso.com.au/article/600455/six-stages-incident-response/
Schou, C., & Hernandez, S. (2014).BInformation Assurance handbook: Effective computer
security and risk management strategies. McGraw-Hill Education Group.
Security Think Tank: 10 control areas to mitigate against malware attacks. (2019). Retrieved
from https://www.computerweekly.com/opinion/Security-Think-Tank-10-control-
areas-to-mitigate-against-malware-attacks
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames ‘culture
of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae. Retrieved
from https://thecyberwire.com/articles/the-equifax-breach-consequences-implications-
and-sequelae.html
Students also viewed