Running Head: EQUIFAX CYBER-ATTACK ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
IT-549 Milestone One: Information Assurance Plan Introduction
EQUIFAX CYBER-ATTACK ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 2
Introduction
Equifax Inc. is a reputed business undertaking that specializes in data
analytics and technology. In the year 2017, cyber attackers had gained access into
the system of the business entity and compromised secretive data and information of
around 143 million American consumers (Equifax Says Cyberattack May Have
Affected 143 Million in the U.S, 2019). They had compromised confidential details
such as name, address, birth date, driver’s license number and Social Security
Number. The incident had gained a lot of attention for all the wrong reasons. In
fact, the cyber-attack on the business entity was considered to be one of the largest
risks relating to the personal and sensitive information of the 21st century (Deanne,
2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an
insight into the importance of the confidentiality, integrity, and availability of
information. The incident which jolted the business organization arose as the business
was using an open-source framework known as Apache Struts for the purpose of
addressing the online disputes relating to its web application. It had a number of
loopholes which exposed its vulnerability to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place
two months prior to the disclosure of the vulnerability of the business entity. In case
a robust cybersecurity model was in place, such an unfateful cyber occurrence could
have been avoided by Equifax Inc. The business undertaking failed to upgrade its
existing systems which ultimately resulted in one of the most severe cyber-attacks in
the history of mankind (Deanne, 2019).
EQUIFAX CYBER-ATTACK ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 3
In order to avoid history from repeating itself, there is a need for Equifax
Inc. to learn from the mistakes and understand the significance of maintaining the
confidentiality, integrity, and availability of information. The creation and maintenance
of a robust and well-designed information assurance plan is beneficial to safeguard
the confidential data and information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was
in place to safeguard the privacy of its stakeholders including the customers. Even
though the business undertaking was one of the most reputed customer credit
reporting agencies, the cyber security complacency at the business organization was
poor and obsolete. In fact, the cyber-attack that took place could have been
prevented only if the business concern had in place an upgraded version of the
security system (Solomon, 2019).
The business concern miserably failed to implement and execute some of the
basic security protocols like the file integrity monitoring technique and the network
segmentation practice. The focus on confidentiality, integrity and availability of
information was negligible due to which the cyber attackers were able to take
advantage of the poor security model of the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information
within the organization has revealed that the CIA triad was weak which allowed the
online attackers to infiltrate sensitive and confidential at relating to millions of
people. The digital certificate which allowed the company to monitor the encrypted
network traffic that flew through its environment had expired almost 19 months prior
to the security breach incident.
Current protocols and policies of the Equifax Inc. organization
EQUIFAX CYBER-ATTACK ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 4
The business undertaking believes that it is its primary responsibility to
protect and safeguard consumer reports. On the official website of the business, it
has claimed to protect the proprietary information including accounting information,
subscriber code, and all the other non-public business details. The business has, in
fact, introduced a number of procedures and policies that its clients need to abide by
in order to access, obtain or distribute the firm’s information (Exhibit A - Internet
Security Requirements, 2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not
clear to what extent the procedure is followed by the concern (Fortune.com, 2019).
In spite of the heavy claims that the business has made about its cybersecurity
approach, it has been involved in a serious of obvious errors and it has failed to
find any fixes for the same.
Some of the potential barriers that hinder the implementation of a new
information assurance plan in the business undertaking include the absence of a strict
security protocol and the presence of a weak internal defense mechanism (Staff,
2019).
References
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to
Protect Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-
happened-protect/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
EQUIFAX CYBER-ATTACK ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 5
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019).
Retrieved from https://www.nytimes.com/2017/09/07/business/equifax-
cyberattack.html
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-
one-year-anniversary/
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames
‘culture of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae.
Retrieved from https://thecyberwire.com/articles/the-equifax-breach-consequences-
implications-and-sequelae.html