Running Head: EQUIFAX 1
IT-549 Milestone Three: Risk Assessment: Equifax
Carlos Delapaz
SNHU
April 14 ,2019
EQUIFAX 2
The term ‘risk assessment’ can be defined as the process of identifying hazards,
negative influences or risk factors are identified. These elements have the potential to cause
harm in a specific context such as a business organization. A proper risk assessment process
is necessary so that a business concern can effectively function in a dynamic and uncertain
environment (Risk Assessment, 2019).
In the information technology context, a wide range of risks and threats can arise and
have an adverse implication on the manner in which a firm functions. Thus there is a need to
do a thorough risk assessment and devise a suitable information assurance plan. The risk
assessment process acts as the core foundation which can help an entity to identify the
various sources of risks and uncertainties that have the ability to jeopardize the sustainability
of the business (National Research Council, 2007).
The main goals of the risk assessment process are as follows:
Identify the risks and gaps and monitoring the performance against the requirements.
Identify and prioritize the IT-related risks to the business concern.
Design an effective and robust IT inventory model that can strengthen the Information
Technology infrastructure of the business undertaking.
Mitigate the identified risks that face the business undertaking by implementing
suitable plans (Monahan & Skeem, 2016).
The environment in which Equifax operates
The Equifax business is primarily involved in the data analytics and technology-based
processes. It enables its clients including business organizations and individuals to make
informed decisions. The customers of the business are enabled to connect with a wide range
of equipment so that they can connect to a network. All these aspects are necessary so that the
business undertaking can offer the best possible credit reference and data intelligence services
in the market (Corporate Social Responsibility | ABout Equifax | Equifax UK, 2019).
EQUIFAX 3
The business undertaking understands that the environment in which it functions
plays a critical role to impact the ultimate service that is offered to its clients. The current
policy of Equifax stresses on the privacy aspects as well as the security aspects so that the
consumers can avail the offerings in a safe and secure environmental setting. Due to the high
level of uncertainty that exists on the IT platform, the business has introduced an effective
online privacy and Cookie policy which will keep the private information of its clients in a
safe manner. In order to secure the clients in the unpredictable business environment, Equifax
has introduced in place a number of security and confidentiality procedures relating to the
storage and the disclosure of the customer information.
Treat Environment of Environment
The information technology environment in which a majority of the business
processes and activities of Equifax are conducted is highly dynamic and unpredictable in
nature. One of the core elements that can endanger the network of the organization is the
‘bring your own device’ BYOD concept. According to an article by Sally Ewalt, even though
this feature can enhance the quality of service for the clients, it is necessary for an
organization like Equifax to take into account the data security aspects (Bring Your Own
Device - But Don't Endanger the Network - Equifax Insights Blog, 2019).
A wide range of security issues can arise that need to be addressed on priority to make
sure that the BYOD model does not hamper the security model of the organization (Privacy
& Cookie Policy | Equifax UK, 2019). The main issues that must be addressed are as follows:
The strong authentication process could be compromised by introducing an outside
device.
Theft of the device with sensitive organizational information
The issues relating to the overall control of the BYOD in the organizational context.
Best approaches for implementing information assurance principles
EQUIFAX 4
The privacy policy of the Equifax organization does not exactly elaborate on the
specific IT security approaches that are implemented at various levels of the entity. But in
order to implement the information assurance principles in the organizational setting, Equifax
must get a detailed understanding of the specific requirements. The business must carefully
select the IT assets that would contain digital information relating to the clients in a safe and
secure manner (Schou & Hernandez, 2014).
The job description relating to the position of the security risk assessment analyst in
Equifax must be elaborately captured. It would enable Equifax to employ suitable personnel
to take care of the IT security infrastructure. There is the need to focus on the environmental
as well as the physical security control measures so that a holistic information assurance
model could be designed for Equifax. The backup and restoration of the digital information
need to be carefully planned so that the organization could have proper control over the
sensitive data and information relating to its clients and customers.
Threats to and vulnerabilities of Equifax – Risk matrix
Since the Equifax business undertaking mainly deals with sensitive and confidential
data relating to its clients, it is extremely necessary to mitigate the dangers that arise in the
digital arena. The risk matrix that has been presented below captures the threats to Equifax
and the vulnerabilities of Equifax in the dynamic technological environmental setting. The
intention is to outline the threats and vulnerabilities that could adversely impact the business.
Similarly, suitable mitigation strategies have also been presented that would help to mitigate
the identified dangers.
Threats Risk of impact Mitigation strategy
Loss of data or
leakage of data
High Equifax can make sure that all the sensitive and
confidential data and information relating to its
clients are securely encrypted. This method would
EQUIFAX 5
make sure that even if the data is compromised by
an unauthorized party, it cannot be decoded.
Malware High The Equifax organization must focus on
establishing robust cybersecurity hygiene. In order
to do so, the business entity needs to employ proper
firewalls, antiviruses and malware software in
place. This holistic technique would help to identify
malware that could compromise the security mode
of the organization.
Phishing High Phishing awareness workshops and training must be
designed so that the employees of Equifax could get
a proper understanding of the security threat. Such a
mitigation strategy would enable them to identify
phishing emails that could adversely affect the
security system of the business organization.
Source: (Security Think Tank: 10 control areas to mitigate against malware attacks,
2019)
References
Bring Your Own Device - But Don't Endanger the Network - Equifax Insights Blog. (2019).
Retrieved from https://insight.equifax.com/bring-your-own-device-but-dont-endanger-
the-network/
Corporate Social Responsibility | ABout Equifax | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/about-equifax/corporate-social-responsibility/en_gb/
Monahan, J., & Skeem, J. L. (2016). Risk assessment in criminal sentencing.GAnnual review
of clinical psychology,G12, 489-513.
EQUIFAX 6
National Research Council. (2007).GScientific review of the proposed risk assessment bulletin
from the Office of Management and Budget. National Academies Press.
Privacy & Cookie Policy | Equifax UK. (2019). Retrieved from
https://www.equifax.co.uk/About-us/Privacy_policy.html
Risk Assessment. (2019). Retrieved from
https://www.ccohs.ca/oshanswers/hsprograms/risk_assessment.html
Schou, C., & Hernandez, S. (2014).GInformation Assurance handbook: Effective computer
security and risk management strategies. McGraw-Hill Education Group.
Security Think Tank: 10 control areas to mitigate against malware attacks. (2019). Retrieved
from https://www.computerweekly.com/opinion/Security-Think-Tank-10-control-
areas-to-mitigate-against-malware-attacks