Running Head: INFORMATION SECURITY aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 1
IT-549 Milestone Two: Information Security Roles and Responsibilities
SNHU
INFORMATION SECURITY aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 2
The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure
that the security infrastructure is robust and up-to-date. In the case of the Equifax
concern, when the cyber attack took place, the CEO of the entity was Mr. Richard
Smith. Soon after the security breach incident had occurred, he was the third senior
executive to have retired from the business undertaking. The other members who had
previously left the organization soon after the cyber incident were Susan Mauldin and
David Webb (Equifax hack: two executives to leave company after breach, 2019).
They were the top security officer and the chief information officer respectively. The
leaders resigned as it was their responsibility to take care of the security environment
of Equifax but they failed to implement a robust security system. Due to their poor
approach, the security breach incident took place which compromised the confidential
data and information of almost 143 million American consumers (Equifax hack: two
executives to leave company after breach, 2019).
The core leadership members of Equifax had not been capable enough to
safeguard the online data and information pertaining to their customers and clients. So
new leaders were appointed where Mr. Paulino do Rego Barros, Jr served as the new
CEO and Mark Feidler was selected as the Non-executive Chairman. The main reason
for the change of leadership in the organization was due to the poor responsiveness
of the former leaders to strengthen the security model firm’s information (Equifax
CEO Richard Smith suddenly decides to ‘retire’, 2019). Richard Smith failed to
design a full proof security model for Equifax due to which a number of
vulnerabilities of the entity were exploited by online hackers. Similarly, Susan
Mauldin and David Webb who were holding vital leadership positions in the
INFORMATION SECURITY aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 3
organizational context were not capable enough to upgrade and strengthen the security
system that was at par with the industry standards.
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information
assurance must be taken into account by the leaders in the evolving organizational
context. In the case of the Equifax entity, the cyber breach exposed the catastrophic
mismanagement of the security infrastructure by its leaders (Equifax CEO Richard
Smith suddenly decides to ‘retire’, 2019). The leaders had failed to take an ethical
and legal stance while designing the security framework. This is evident from the fact
that they had failed to patch a well-known security loophole which is the main
reasons why the online hackers were able to gain access into the organizational
system.
The main legal and ethical considerations that the new leaders of the entity
took after the cyber attack include the introduction of the TrustedID Premier services.
This new technique will basically enable the customers to the business entity to
determine whether they have been adversely affected by an incident or not. In case
robust ethical and legal elements are not taken into account by organizations, adverse
implications can be faced by the affected organization especially, the leaders (Rep.
Correa Reiterates Need For Federal Data Breach Laws, 2019). For instance, federal
law has been designed in California after the data breach incident which crippled the
Equifax business entity. Businesses must notify the Federal Bureau of Investigation
(FBI), Federal Trade Commission (FTC) and other agencies about the data breach
incident. aa aa
The key components of information assurance
INFORMATION SECURITY aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 4
In order to establish a robust security system in the organizational context,
business undertakings need to have proper and updated security policies that revolve
around confidentiality, integrity, and availability of information. In the Equifax entity,
the security policy was not well designed. In fact, the business undertaking failed to
match the security model with its market growth (Bloomberg - Are you a robot?,
2019). The organization did not have clear lines of authority due to which a number
of gaps existed in the security system. Similarly, the organization that specialized in
data analytics and technology failed to modernize its technology-based security model
with the evolving times and changing the technological landscape. As per reports, if
the business organization would have been able to take suitable actions against the
observable security loopholes prior to the cyber incident, the data breach accident
could have been totally prevented.
On the highly dynamic and unpredictable technological business setting,
business undertakings need to focus on the confidentiality aspect, integrity aspect and
availability aspect of technology. These key components of information assurance
must be ingrained so that a safe and secure It infrastructure can be created by a
business entity.
References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
INFORMATION SECURITY aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 5
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348