Running Head: EQUIFAX CYBER-ATTACK aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa 1
IT-549 Milestone One: Information Assurance Plan Introduction
SNHU
EQUIFAX CYBER-ATTACK aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 2
Introduction
Equifax Inc. is a reputed business undertaking that specializes in data analytics
and technology. In the year 2017, cyber attackers had gained access into the system
of the business entity and compromised secretive data and information of around 143
million American consumers (Equifax Says Cyberattack May Have Affected 143
Million in the U.S, 2019). They had compromised confidential details such as name,
address, birth date, driver’s license number and Social Security Number. The incident
had gained a lot of attention for all the wrong reasons. In fact, the cyber-attack on
the business entity was considered to be one of the largest risks relating to the
personal and sensitive information of the 21st century (Deanne, 2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an
insight into the importance of the confidentiality, integrity, and availability of
information. The incident which jolted the business organization arose as the business
was using an open-source framework known as Apache Struts for the purpose of
addressing the online disputes relating to its web application. It had a number of
loopholes which exposed its vulnerability to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place
two months prior to the disclosure of the vulnerability of the business entity. In case
a robust cybersecurity model was in place, such an unfateful cyber occurrence could
have been avoided by Equifax Inc. The business undertaking failed to upgrade its
existing systems which ultimately resulted in one of the most severe cyber-attacks in
the history of mankind (Deanne, 2019).
In order to avoid history from repeating itself, there is a need for Equifax Inc.
to learn from the mistakes and understand the significance of maintaining the
EQUIFAX CYBER-ATTACK aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 3
confidentiality, integrity, and availability of information. The creation and maintenance
of a robust and well-designed information assurance plan is beneficial to safeguard
the confidential data and information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was
in place to safeguard the privacy of its stakeholders including the customers. Even
though the business undertaking was one of the most reputed customer credit
reporting agencies, the cyber security complacency at the business organization was
poor and obsolete. In fact, the cyber-attack that took place could have been prevented
only if the business concern had in place an upgraded version of the security system
(Solomon, 2019).
The business concern miserably failed to implement and execute some of the
basic security protocols like the file integrity monitoring technique and the network
segmentation practice. The focus on confidentiality, integrity and availability of
information was negligible due to which the cyber attackers were able to take
advantage of the poor security model of the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information
within the organization has revealed that the CIA triad was weak which allowed the
online attackers to infiltrate sensitive and confidential at relating to millions of
people. The digital certificate which allowed the company to monitor the encrypted
network traffic that flew through its environment had expired almost 19 months prior
to the security breach incident.
Current protocols and policies of the Equifax Inc. organization
The business undertaking believes that it is its primary responsibility to protect
and safeguard consumer reports. On the official website of the business, it has
EQUIFAX CYBER-ATTACK aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 4
claimed to protect the proprietary information including accounting information,
subscriber code, and all the other non-public business details. The business has, in
fact, introduced a number of procedures and policies that its clients need to abide by
in order to access, obtain or distribute the firm’s information (Exhibit A - Internet
Security Requirements, 2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not
clear to what extent the procedure is followed by the concern (Fortune.com, 2019). In
spite of the heavy claims that the business has made about its cybersecurity approach,
it has been involved in a serious of obvious errors and it has failed to find any fixes
for the same.
Some of the potential barriers that hinder the implementation of a new
information assurance plan in the business undertaking include the absence of a strict
security protocol and the presence of a weak internal defense mechanism (Staff,
2019).
References
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to
Protect Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-
happened-protect/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019).
Retrieved from https://www.nytimes.com/2017/09/07/business/equifax-
cyberattack.html
EQUIFAX CYBER-ATTACK aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 5
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-
one-year-anniversary/
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames
‘culture of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae.
Retrieved from https://thecyberwire.com/articles/the-equifax-breach-consequences-
implications-and-sequelae.html