Running Head: EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g 1
IT-549 Milestone Four : Statements of Policy
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 2
Lately, a large number of business undertakings have fallen victims to cyber
attacks. One of the most well-known cyber incidents that had jolted the business setting
involved the Equifax firm. A number of protocols have been recommended for the firm.
Similarly, various mitigating factors to the organization have been highlighted as well. The
main protocols that have been captured here are the Incident Response protocols, Disaster
Response protocols, Access control protocols, and maintenance plan. The intention is to
design a robust information assurance plan so that such kinds of cyber incidents can be
managed and effectively tackled in the future by Equifax.
Incident Response protocols
The incident response protocol would enable the firm to properly respond and react
to such kinds of events in case they arise in the future. In order to do so, it is extremely
vital to involve organizational personnel in the security process. Equifax must implement a
functional incident response protocol so that the employees will be empowered to respond
to such an event. It would also allow them to take the necessary steps to minimize the
extent of the damage (Incident Response Protocol: Information Technology - Northwestern
University, 2019).
Some of the key stages that are involved in the incident response protocol include
the preparation by the response team, the identification of the environment, the
containment of the damage, the eradication of the threat from the system, recovery and
learning lessons from the incident (Response, 2019).
Justification of the Incident Response protocols
The protocol is necessary as it can help an organization to be ready to face a cyber
threat. Today, such threats can arise before any firm. The protocol will make sure that the
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 3
firm and its employees know the steps that they need to take so that they can tactfully
respond to the situation and control the damage. g g
Disaster Response protocols
The business undertakings that work in the global context such as Equifax must
devise suitable disaster response protocols. These protocols will primarily help to devise a
coordinated plan across the various business units which will help to face the danger in the
cyber setting. Equifax conducts its data analytics and technology function in almost 24
nations (Myers, 2019).
Some of the main elements that can be introduced by Equifax in the Disaster
Response protocol include segregating the authority among professionals to close a site.
Similarly, all the security criteria must be clearly defined so that the leaders can act in an
independent manner. The firm must make sure that there exists no ambiguity while
distributing responsibilities among the organizational personnel of Equifax. In various
locations in which Equifax functions, it must implement streamlined and uniform disaster
response protocols. It would enable the firm to respond in an integrated manner to tackle
vulnerabilities in the cyber setting.
Justification of the Disaster Response protocols
The relevance of proper disaster response protocol would be extremely vital for the
Equifax concern. This element of the security policy would make sure that all the
individuals are aware of their exact roles and responsibilities when a threat in the cyber
setting arises. It would enable them to get a detailed insight into various angles from where
the threat could loom such as the attack on cloud services, mobile device attack, and
ghostware attack (Emergency Management for Cyber Attacks, 2019).
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 4
Access control protocols
Equifax would have to establish a number of access control protocols on its policy
so that specific individuals would have the authority to have access to certain areas of the
IT ecosystem. This protocol would ensure that professionals would be able to meet certain
criteria before they gain access to the system. This control mechanism would enable the
business to introduce innovative elements such as PIN, fingerprints identification model or
iris identification model.
The access control protocol of Equifax must be developed so that the firm could be
well equipped to defend itself from internal threats as well as external threats. The protocol
would facilitate the business concern to involve the appropriate team members in the attack
mitigation plans (my Social Security | Social Security Administration, 2019). A vital
practice that the business undertaking must keep in mind relates to the regular drafting,
implementing and upgrading of the cybersecurity plan. Such an approach would play an
extremely critical role to prepare the firm to face uncertain cyber events. g
Justification of the access control protocols
Equifax needs to introduce the access control protocols in the security policy as it
would strengthen its security model in the uncertain cyber setting. These protocols would
safeguard the firm from internal threats as well as external risks. It would make sure that
power to have access to certain sensitive IT areas is in the hands of a few individuals.
Such an approach could minimize the vulnerability of the business in the dynamic cyber
setting.
Recommendation for maintaining the information assurance plan
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 5
In order to maintain the robust information assurance plan, Equifax must make sure
that the appropriate policies, practices, standards, and guidelines are always followed by
the organizational personnel.
The policies and security component must be matched with the firm’s risk profile.
A robust risk assessment model must be designed comprising of implementation,
monitoring, testing, and reporting elements. It would help to maintain the information
assurance plan of Equifax firm. g
In addition to the firm’s information security policy, Equifax must also follow the
security standards that are applicable at the industry level. For example, in case the firm
deals with branded credit cards from the clients, it must make sure to follow the Payment
Card Industry Data Security Standard (PCI DSS).
Since the information security policies and protocols would act as the backbone of
Equifax’s information assurance plan. It is necessary to follow the recommendations so
that the maintenance of the assurance plan could be possible (How to Develop & Maintain
Information Security Policies & Procedures, 2019).
Justification of the maintainable plan
The maintenance plan has been designed to make sure that the information
assurance plan of Equifax would play a vital role and defend the firm and its Information
Technology ecosystem in the unpredictable cyber setting. By properly following the
security model, the vulnerability of the firm could be controlled in a better manner. The
proper maintenance of the assurance plan by the business undertaking would play a vital
role to strengthen its stance against cyber attackers and hackers who could exploit the
vulnerabilities of the business concern. The proper maintenance of the information
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 6
assurance plan would help the firm to know the current status of the security system. Thus
it could strengthen, upgrade and maintain the quality of the information assurance plan. In
the unpredictable cyber setting, the role of the assurance plan would be indispensable in
nature for Equifax. It would help the business undertaking to prevent similar kind of attack
that had previously affected its brand reputation and crippled its business activities.
References
Emergency Management for Cyber Attacks. (2019). Retrieved from
https://safetymanagement.eku.edu/blog/emergency-management-for-cyber-attacks/
How to Prepare For and Respond To A Cyber Attack: Have A Disaster Recovery Plan |
OlenderFeldman LLP. (2019). Retrieved from https://www.olenderfeldman.com/how-
to-prepare-for-and-respond-to-a-cyber-attack-have-a-disaster-recovery-plan/
How to Develop & Maintain Information Security Policies & Procedures. (2019).
Retrieved from https://www.bankinfosecurity.com/webinars/how-to-develop-maintain-
information-security-policies-procedures-w-135
Incident Response Protocol: Information Technology - Northwestern University. (2019).
Retrieved from https://www.it.northwestern.edu/policies/incident.html
Response, T. (2019). The Six Stages of Incident Response. Retrieved from
https://www.cso.com.au/article/600455/six-stages-incident-response/
Myers, L. (2019). How many people outside the US are affected by the Equifax breach? |
WeLiveSecurity. Retrieved from https://www.welivesecurity.com/2017/09/15/many-
people-outside-u-s-affected-equifax-breach/
EQUIFAX g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g 7
my Social Security | Social Security Administration. (2019). Retrieved from
https://www.ssa.gov/myaccount/