Running Head: SECURITY LAWS 1
IT 552 : Module One Assignment
Carlos Delapaz
SNHU
June 2 ,2019
SECURITY LAWS
2
Suspect – Fujie Wang
Security laws
A number of security laws exist that relate to the criminal activities that were carried out by
Fujie Wang and his hacking team. As per security laws, business undertakings need to protect the
sensitive and confidential data and information relating to the business activities and customers.
The CIA triad can be implemented by business firms so that the core security elements such as
confidentiality, integrity and availability of information security can be maintained (What is
confidentiality, integrity, and availability (CIA triad)? - Definition from WhatIs.com, 2019). It is a
well-known security policy that needs to be employed by business undertakings so that the
vulnerability of firms can be managed. Such laws have been designed so that the scope of cyber
criminals like Wang can be reduced in the best way possible (University, 2019).
Description of the committed crimes by Fujie Wang
Fujie Wang was involved in the conspiracy to commit fraud and other related activities that
are linked to computers and technology. He was basically the member of a hacking group in China
that carried out a number of intrusion campaigns. These intrusion campaigns primarily targeted the
computer systems of large business undertakings from the United States of America. It has been
alleged that between February 2014 and January 2105, the group along with Wang hatched the
conspiracy to intentionally access the computer networks for stealing confidential data and
information of almost 78.8 million people (Wanted by FBI- FUJIE WANG, 2019). Some of the
details that that stolen by the group include the names, date of births, the health identification
numbers, addresses, Social Security Numbers and employment information. After such confidential
information had been stolen, they were kept in encrypted files and sent to a number of Chinese
destinations.
Exploited security vulnerabilities
SECURITY LAWS
3
The cyber-attacks that were carried out by Fujie Wang and his group basically exploited the
vulnerability that arse due to the existence of out-dated security system. For example, Wang was
involved in hacking the popular health insurance giant Anthem Inc. This cyber-attack which jolted
the health sector took place as the business undertaking failed to take the necessary steps to protect
the confidential business information and the customer data (Newman et al., 2019).
According to experts, the security vulnerability arose due to the lack of protection of data in
computers by using encryption (Anthem Hacking Points to Security Vulnerability of Health Care
Industry, 2019). Even though the firm had safeguarded medical information through encryptions
while sharing these details and information outside of the business database, it failed to implement
the same security model while operating inside its very own Information Technology infrastructure
(Anthem Hacking Points to Security Vulnerability of Health Care Industry, 2019). Thus the various
cyber-attacks in which Fujie Wangwas involved, security vulnerabilities arose due to the lack of
implementation of a robust and upgraded cyber security model.
Proposal relating to incident precautions
In order to prevent such an incident from repeating, a number of precautionary measures can
be taken. For example, business undertakings need to employ updated cyber security models so that
the opportunity before cyber criminals and attackers can be reduced. Most of the time online
attackers are able to get an unauthorized access to the computer systems of business entities due to
the lack of a proper cyber security framework. Thus there is the need to regularly upgrade the
security model, protect sensitive data and information through encryption and train the employees
on various cyber security strategic approaches. Such a cyber security approach can be implemented
so that the hacking incidents that were carried out by Fujie Wang and his team can be avoided in
the near future. In addition to this, there is the need for business entities to flow the security
guidelines and standards that have been established in the respective industries. By following the
SECURITY LAWS
4
guidelines, business firms can strengthen their cyber security framework and minimize their
security vulnerability in the process (Wanted by FBI- FUJIE WANG, 2019).
SECURITY LAWS
5
References
Anthem Hacking Points to Security Vulnerability of Health Care Industry. (2019). Retrieved from
https://www.nytimes.com/2015/02/06/business/experts-suspect-lax-security-left-anthem-
vulnerable-to-hackers.html?
action=click&module=RelatedCoverage&pgtype=Article®ion=Footer
University, G. (2019). Confidentiality, Integrity, and Availability (CIA) triad | CCNA Security.
Retrieved from https://geek-university.com/ccna-security/confidentiality-integrity-and-
availability-cia-triad/
Newman, L., Lapowsky, I., Tufekci, Z., & Barrett, B. (2019). Indictment Alleges Who Hacked
Anthem, but Not Why. Retrieved from https://www.wired.com/story/anthem-hack-
indictment-china/
What is confidentiality, integrity, and availability (CIA triad)? - Definition from WhatIs.com.
(2019). Retrieved from https://whatis.techtarget.com/definition/Confidentiality-integrity-and-
availability-CIA
Wanted by FBI- FUJIE WANG. (2019). Retrieved from https://www.fbi.gov/wanted/cyber/fujie-
wang/@@download.pdf