Running Head: INFORMATION SECURITY g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g 1
IT-549 Milestone Two: Information Security Roles and Responsibilities
INFORMATION SECURITY g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 2
The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure that the
security infrastructure is robust and up-to-date. In the case of the Equifax concern, when
the cyber attack took place, the CEO of the entity was Mr. Richard Smith. Soon after the
security breach incident had occurred, he was the third senior executive to have retired
from the business undertaking. The other members who had previously left the
organization soon after the cyber incident were Susan Mauldin and David Webb (Equifax
hack: two executives to leave company after breach, 2019). They were the top security
officer and the chief information officer respectively. The leaders resigned as it was their
responsibility to take care of the security environment of Equifax but they failed to
implement a robust security system. Due to their poor approach, the security breach
incident took place which compromised the confidential data and information of almost
143 million American consumers (Equifax hack: two executives to leave company after
breach, 2019).
The core leadership members of Equifax had not been capable enough to safeguard
the online data and information pertaining to their customers and clients. So new leaders
were appointed where Mr. Paulino do Rego Barros, Jr served as the new CEO and Mark
Feidler was selected as the Non-executive Chairman. The main reason for the change of
leadership in the organization was due to the poor responsiveness of the former leaders to
strengthen the security model firm’s information (Equifax CEO Richard Smith suddenly
decides to ‘retire’, 2019). Richard Smith failed to design a full proof security model for
Equifax due to which a number of vulnerabilities of the entity were exploited by online
hackers. Similarly, Susan Mauldin and David Webb who were holding vital leadership
positions in the organizational context were not capable enough to upgrade and strengthen
the security system that was at par with the industry standards.
INFORMATION SECURITY g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 3
The key ethical and legal considerations related to information assurance
A number of key ethical and legal considerations relating to information assurance
must be taken into account by the leaders in the evolving organizational context. In the
case of the Equifax entity, the cyber breach exposed the catastrophic mismanagement of
the security infrastructure by its leaders (Equifax CEO Richard Smith suddenly decides to
‘retire’, 2019). The leaders had failed to take an ethical and legal stance while designing
the security framework. This is evident from the fact that they had failed to patch a well-
known security loophole which is the main reasons why the online hackers were able to
gain access into the organizational system.
The main legal and ethical considerations that the new leaders of the entity took
after the cyber attack include the introduction of the TrustedID Premier services. This new
technique will basically enable the customers to the business entity to determine whether
they have been adversely affected by an incident or not. In case robust ethical and legal
elements are not taken into account by organizations, adverse implications can be faced by
the affected organization especially, the leaders (Rep. Correa Reiterates Need For Federal
Data Breach Laws, 2019). For instance, federal law has been designed in California after
the data breach incident which crippled the Equifax business entity. Businesses must notify
the Federal Bureau of Investigation (FBI), Federal Trade Commission (FTC) and other
agencies about the data breach incident. g g
The key components of information assurance
In order to establish a robust security system in the organizational context, business
undertakings need to have proper and updated security policies that revolve around
confidentiality, integrity, and availability of information. In the Equifax entity, the security
policy was not well designed. In fact, the business undertaking failed to match the security
model with its market growth (Bloomberg - Are you a robot?, 2019). The organization did
INFORMATION SECURITY g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g 4
not have clear lines of authority due to which a number of gaps existed in the security
system. Similarly, the organization that specialized in data analytics and technology failed
to modernize its technology-based security model with the evolving times and changing
the technological landscape. As per reports, if the business organization would have been
able to take suitable actions against the observable security loopholes prior to the cyber
incident, the data breach accident could have been totally prevented.
On the highly dynamic and unpredictable technological business setting, business
undertakings need to focus on the confidentiality aspect, integrity aspect and availability
aspect of technology. These key components of information assurance must be ingrained
so that a safe and secure It infrastructure can be created by a business entity.
References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348