Running Head: EQUIFAX CYBER-ATTACK g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g 1
IT-549 Milestone One: Information Assurance Plan Introduction
EQUIFAX CYBER-ATTACK g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g 2
Introduction
Equifax Inc. is a reputed business undertaking that specializes in data analytics and
technology. In the year 2017, cyber attackers had gained access into the system of the
business entity and compromised secretive data and information of around 143 million
American consumers (Equifax Says Cyberattack May Have Affected 143 Million in the
U.S, 2019). They had compromised confidential details such as name, address, birth date,
driver’s license number and Social Security Number. The incident had gained a lot of
attention for all the wrong reasons. In fact, the cyber-attack on the business entity was
considered to be one of the largest risks relating to the personal and sensitive information
of the 21st century (Deanne, 2019).
Overview of the goals and objectives
The information assurance plan has been designed with the intention to get an
insight into the importance of the confidentiality, integrity, and availability of information.
The incident which jolted the business organization arose as the business was using an
open-source framework known as Apache Struts for the purpose of addressing the online
disputes relating to its web application. It had a number of loopholes which exposed its
vulnerability to cyber hackers (Deanne, 2019).
The unfolding of the cyber breach indicated that the attack has taken place two
months prior to the disclosure of the vulnerability of the business entity. In case a robust
cybersecurity model was in place, such an unfateful cyber occurrence could have been
avoided by Equifax Inc. The business undertaking failed to upgrade its existing systems
which ultimately resulted in one of the most severe cyber-attacks in the history of mankind
(Deanne, 2019).
In order to avoid history from repeating itself, there is a need for Equifax Inc. to
learn from the mistakes and understand the significance of maintaining the confidentiality,
EQUIFAX CYBER-ATTACK g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g 3
integrity, and availability of information. The creation and maintenance of a robust and
well-designed information assurance plan is beneficial to safeguard the confidential data
and information.
Assessment of confidentiality, integrity, and availability of information
The cybersecurity model of Equifax Inc. was of an inferior quality which was in
place to safeguard the privacy of its stakeholders including the customers. Even though the
business undertaking was one of the most reputed customer credit reporting agencies, the
cyber security complacency at the business organization was poor and obsolete. In fact, the
cyber-attack that took place could have been prevented only if the business concern had in
place an upgraded version of the security system (Solomon, 2019).
The business concern miserably failed to implement and execute some of the basic
security protocols like the file integrity monitoring technique and the network segmentation
practice. The focus on confidentiality, integrity and availability of information was
negligible due to which the cyber attackers were able to take advantage of the poor
security model of the business entity (Solomon, 2019).
The assessment of the confidentiality, integrity, and availability of information
within the organization has revealed that the CIA triad was weak which allowed the online
attackers to infiltrate sensitive and confidential at relating to millions of people. The digital
certificate which allowed the company to monitor the encrypted network traffic that flew
through its environment had expired almost 19 months prior to the security breach
incident.
Current protocols and policies of the Equifax Inc. organization
The business undertaking believes that it is its primary responsibility to protect and
safeguard consumer reports. On the official website of the business, it has claimed to
protect the proprietary information including accounting information, subscriber code, and
EQUIFAX CYBER-ATTACK g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g 4
all the other non-public business details. The business has, in fact, introduced a number of
procedures and policies that its clients need to abide by in order to access, obtain or
distribute the firm’s information (Exhibit A - Internet Security Requirements, 2019).
Even though the business has made claims about safeguarding confidential
information pertaining to its clients and customers by encrypting the same, it is not clear to
what extent the procedure is followed by the concern (Fortune.com, 2019). In spite of the
heavy claims that the business has made about its cybersecurity approach, it has been
involved in a serious of obvious errors and it has failed to find any fixes for the same.
Some of the potential barriers that hinder the implementation of a new information
assurance plan in the business undertaking include the absence of a strict security protocol
and the presence of a weak internal defense mechanism (Staff, 2019).
References
Deanne, M. (2019). The Equifax Cyber Attack - How It Happened and How to Protect
Yourself. Retrieved from https://interwork.com/equifax-cyber-attack-happened-
protect/
Exhibit A - Internet Security Requirements. (2019). Retrieved from
https://www.equifax.com/eport/internet-security/
Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (2019). Retrieved
from https://www.nytimes.com/2017/09/07/business/equifax-cyberattack.html
Fortune.com. (2019). Retrieved from http://fortune.com/2018/09/07/equifax-data-breach-
one-year-anniversary/
Solomon, H. (2019). Congress report: Equifax breach ‘entirely preventable,’ blames
‘culture of cyber security complacency’. Retrieved from
https://www.itworldcanada.com/article/congress-report-equifax-breach-entirely-
preventable-blames-culture-of-cyber-security-complacency/412857
EQUIFAX CYBER-ATTACK g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g 5
Staff, T. (2019). The Equifax breach: consequences, implications, and sequelae. Retrieved
from https://thecyberwire.com/articles/the-equifax-breach-consequences-implications-
and-sequelae.html