Running Head: INFORMATION SECURITY e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e 1
IT-549 Milestone Two: Information Security Roles and Responsibilities
SNHU
INFORMATION SECURITY e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure that
the security infrastructure is robust and up-to-date. In the case of the Equifax concern,
when the cyber attack took place, the CEO of the entity was Mr. Richard Smith. Soon
after the security breach incident had occurred, he was the third senior executive to have
retired from the business undertaking. The other members who had previously left the
organization soon after the cyber incident were Susan Mauldin and David Webb
(Equifax hack: two executives to leave company after breach, 2019). They were the top
security officer and the chief information officer respectively. The leaders resigned as it
was their responsibility to take care of the security environment of Equifax but they
failed to implement a robust security system. Due to their poor approach, the security
breach incident took place which compromised the confidential data and information of
almost 143 million American consumers (Equifax hack: two executives to leave
company after breach, 2019).
The core leadership members of Equifax had not been capable enough to
safeguard the online data and information pertaining to their customers and clients. So
new leaders were appointed where Mr. Paulino do Rego Barros, Jr served as the new
CEO and Mark Feidler was selected as the Non-executive Chairman. The main reason
for the change of leadership in the organization was due to the poor responsiveness of
the former leaders to strengthen the security model firm’s information (Equifax CEO
Richard Smith suddenly decides to ‘retire’, 2019). Richard Smith failed to design a full
proof security model for Equifax due to which a number of vulnerabilities of the entity
were exploited by online hackers. Similarly, Susan Mauldin and David Webb who were
holding vital leadership positions in the organizational context were not capable enough
INFORMATION SECURITY e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
to upgrade and strengthen the security system that was at par with the industry
standards.
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information
assurance must be taken into account by the leaders in the evolving organizational
context. In the case of the Equifax entity, the cyber breach exposed the catastrophic
mismanagement of the security infrastructure by its leaders (Equifax CEO Richard Smith
suddenly decides to ‘retire’, 2019). The leaders had failed to take an ethical and legal
stance while designing the security framework. This is evident from the fact that they
had failed to patch a well-known security loophole which is the main reasons why the
online hackers were able to gain access into the organizational system.
The main legal and ethical considerations that the new leaders of the entity took
after the cyber attack include the introduction of the TrustedID Premier services. This
new technique will basically enable the customers to the business entity to determine
whether they have been adversely affected by an incident or not. In case robust ethical
and legal elements are not taken into account by organizations, adverse implications can
be faced by the affected organization especially, the leaders (Rep. Correa Reiterates
Need For Federal Data Breach Laws, 2019). For instance, federal law has been designed
in California after the data breach incident which crippled the Equifax business entity.
Businesses must notify the Federal Bureau of Investigation (FBI), Federal Trade
Commission (FTC) and other agencies about the data breach incident. e e
The key components of information assurance
In order to establish a robust security system in the organizational context,
business undertakings need to have proper and updated security policies that revolve
around confidentiality, integrity, and availability of information. In the Equifax entity,
INFORMATION SECURITY e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
the security policy was not well designed. In fact, the business undertaking failed to
match the security model with its market growth (Bloomberg - Are you a robot?, 2019).
The organization did not have clear lines of authority due to which a number of gaps
existed in the security system. Similarly, the organization that specialized in data
analytics and technology failed to modernize its technology-based security model with
the evolving times and changing the technological landscape. As per reports, if the
business organization would have been able to take suitable actions against the
observable security loopholes prior to the cyber incident, the data breach accident could
have been totally prevented.
On the highly dynamic and unpredictable technological business setting, business
undertakings need to focus on the confidentiality aspect, integrity aspect and availability
aspect of technology. These key components of information assurance must be ingrained
so that a safe and secure It infrastructure can be created by a business entity.
References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348
INFORMATION SECURITY e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5