Solved by verified expert:1. What policies and procedures appear to have been lacking at Equifax?2. Do any of the policies and procedures address what the executives are accused of doing?3. Why did they wait so long to inform the public?Legally what are they required to do?4. How could this have been avoided?Please see the file attached.
extra_credit_for_operations_security.docx
Unformatted Attachment Preview
In July of 2017, Equifax suffered a security breach. It is estimated that over 143 million
Americans had their birthdate, social security number, addresses and driver’s license numbers
stolen. In addition, over 206,000 credit card numbers with PII attached were accessed and
~182,000 people involved in credit card disputes. In the latter cases, customers in the UK and
Canada were also affected.
It is said that a patch was not applied to the Apache Struts and that vulnerability allowed the
hackers to break in. In addition, the breach occurred between May and July of 2017, but was not
reported to the public until September after Equifax had hired Mandiant to do an internal
investigation of what had happened.
Also three Equifax executives sold off almost US $1.8 Million of their personal shares a month
prior to the public disclosures.
Equifax set up a website for people to use https://www.equifaxsecurity2017.com which later was
classified as insecure and built almost like a phishing website.
Using what we have learned in this class, write a 2 to 3 page paper that addresses:
•
•
•
•
What policies and procedures appear to have been lacking at Equifax?
Do any of the policies and procedures address what the executives are accused of doing?
Why did they wait so long to inform the public? Legally what are they required to do?
How could this have been avoided?
State your premise and supporting arguments, etc. clearly.
Note that I will take off up to 10% of the grade for poor grammar and misspellings. So be sure to
run grammar and spell check
Resources:
Giant Equifax Data Breach, http://money.cnn.com/2017/09/07/technology/business/equifax-databreach/index.html
https://en.wikipedia.org/wiki/Equifax
…
Purchase answer to see full
attachment