Running Head: INFORMATION SECURITY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT-549 Milestone Two: Information Security Roles and Responsibilities
SNHU
INFORMATION SECURITY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 2
The role of the key leaders within the Equifax organization
The leaders of an organization play an extremely critical role to make sure that the
security infrastructure is robust and up-to-date. In the case of the Equifax concern, when the
cyber attack took place, the CEO of the entity was Mr. Richard Smith. Soon after the security
breach incident had occurred, he was the third senior executive to have retired from the
business undertaking. The other members who had previously left the organization soon after
the cyber incident were Susan Mauldin and David Webb (Equifax hack: two executives to
leave company after breach, 2019). They were the top security officer and the chief
information officer respectively. The leaders resigned as it was their responsibility to take
care of the security environment of Equifax but they failed to implement a robust security
system. Due to their poor approach, the security breach incident took place which
compromised the confidential data and information of almost 143 million American
consumers (Equifax hack: two executives to leave company after breach, 2019).
The core leadership members of Equifax had not been capable enough to safeguard
the online data and information pertaining to their customers and clients. So new leaders
were appointed where Mr. Paulino do Rego Barros, Jr served as the new CEO and Mark
Feidler was selected as the Non-executive Chairman. The main reason for the change of
leadership in the organization was due to the poor responsiveness of the former leaders to
strengthen the security model firm’s information (Equifax CEO Richard Smith suddenly
decides to ‘retire’, 2019). Richard Smith failed to design a full proof security model for
Equifax due to which a number of vulnerabilities of the entity were exploited by online
hackers. Similarly, Susan Mauldin and David Webb who were holding vital leadership
positions in the organizational context were not capable enough to upgrade and strengthen
the security system that was at par with the industry standards.
The key ethical and legal considerations related to information assurance
INFORMATION SECURITY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 3
A number of key ethical and legal considerations relating to information assurance
must be taken into account by the leaders in the evolving organizational context. In the case
of the Equifax entity, the cyber breach exposed the catastrophic mismanagement of the
security infrastructure by its leaders (Equifax CEO Richard Smith suddenly decides to
‘retire’, 2019). The leaders had failed to take an ethical and legal stance while designing the
security framework. This is evident from the fact that they had failed to patch a well-known
security loophole which is the main reasons why the online hackers were able to gain access
into the organizational system.
The main legal and ethical considerations that the new leaders of the entity took after
the cyber attack include the introduction of the TrustedID Premier services. This new
technique will basically enable the customers to the business entity to determine whether they
have been adversely affected by an incident or not. In case robust ethical and legal elements
are not taken into account by organizations, adverse implications can be faced by the affected
organization especially, the leaders (Rep. Correa Reiterates Need For Federal Data Breach
Laws, 2019). For instance, federal law has been designed in California after the data breach
incident which crippled the Equifax business entity. Businesses must notify the Federal
Bureau of Investigation (FBI), Federal Trade Commission (FTC) and other agencies about
the data breach incident. f f
The key components of information assurance
In order to establish a robust security system in the organizational context, business
undertakings need to have proper and updated security policies that revolve around
confidentiality, integrity, and availability of information. In the Equifax entity, the security
policy was not well designed. In fact, the business undertaking failed to match the security
model with its market growth (Bloomberg - Are you a robot?, 2019). The organization did
not have clear lines of authority due to which a number of gaps existed in the security system.
INFORMATION SECURITY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 4
Similarly, the organization that specialized in data analytics and technology failed to
modernize its technology-based security model with the evolving times and changing the
technological landscape. As per reports, if the business organization would have been able to
take suitable actions against the observable security loopholes prior to the cyber incident, the
data breach accident could have been totally prevented.
On the highly dynamic and unpredictable technological business setting, business
undertakings need to focus on the confidentiality aspect, integrity aspect and availability
aspect of technology. These key components of information assurance must be ingrained so
that a safe and secure It infrastructure can be created by a business entity.
References
Bloomberg - Are you a robot?. (2019). Retrieved from
https://www.bloomberg.com/news/articles/2018-12-10/equifax-failed-to-adjust-
security-to-rapid-growth-report-says
Equifax hack: two executives to leave company after breach. (2019). Retrieved from
https://www.theguardian.com/technology/2017/sep/15/equifax-hack-susan-mauldin-
david-webb
Equifax CEO Richard Smith suddenly decides to ‘retire’. (2019). Retrieved from
https://www.engadget.com/2017/09/26/equifax-ceo-retires-after-massive-data-breach/
Rep. Correa Reiterates Need For Federal Data Breach Laws. (2019). Retrieved from
https://medium.com/congressman-lou-correa/rep-correa-reiterates-need-for-federal-
data-breach-laws-22bacdc57348