• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Syllabus
  • Schedule
    • First Half of Semester
      • Week 1: IT Governance
      • Week 2: IT’s Role and the Control Environment
      • Week 3: Business / IT Alignment
      • Week 4: Enterprise Architecture and IT Strategy
      • Week 5: Project Portfolio Management
      • Week 6: Monitoring & Evaluating IT
      • Week 7: Policy
    • Second Half of Semeter
      • Week 8: IT Services and Quality
      • Week 9: IT Outsourcing
      • Week 10: Cloud Computing
      • Week 11: IT Risk
      • Week 12: IT Security
      • Week 13: Disaster Recovery & Business Continuity
  • Assignments
    • Project #1
      • P Sample 1
      • P Sample 2
    • Project #2
      • AP Sample 1
      • AP Sample 2
  • Webex Session
  • Harvard Readings

MIS 5202 IT Governance

Temple University

Interesting Article in Today’s WSJ on Cyber Security

September 18, 2017 by Richard Flanagan 1 Comment

The WSJ had a nice article on the Equifax breach.  Lots of lessons in there but most are things they should have known.

 

 

Filed Under: Week 12: IT Security Tagged With:

Reader Interactions

Comments

  1. Pascal Allison says

    November 12, 2017 at 7:48 am

    The WSJ had a nice article on the Equifax breach. Lots of lessons in there but most are things they should have known.

    Equifax known about the vulnerability or exposure before the attack. Now, if the decision was intentional (accept the risk) or not, the risk was managed poorly. Equifax is in possession of Personal Identifiable Information (PII), Equifax is under a legal obligation to protect information, their business, and customers which they failed to do.

    Learn learned: Doing the right thing, doing things right. Do it right the first time.

    Organizations need to conduct an effective and efficient risk evaluation and cost analysis (risk management and enterprise risk management) to determine how much risk the organization can accept and the cost to accept the risk.

    When the analysis and evaluation are finalized or when risk is detected, a decision much is made:

    Avoid the risk if possible, reduce, share, accept it.

    Accepting the risk should be the last option.

    Accepting risk is a good risk management action, but it is not a chance to take without careful evaluation. Because there is a lot at stick: ethics, morals, lawsuit, and finance. If the cost to avoid it is less than the cost to repair it, do not allow it to break.

    Reply

Leave a Reply to Pascal Allison Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Weekly Discussions

  • Class Administration (10)
  • Week 01: IT Governance (3)
  • Week 02: IT's Role & the Control Environment (5)
  • Week 03: IT Administrative Controls (3)
  • Week 04: Enterprise Architecture (3)
  • Week 05:IT Strategy (3)
  • Week 06: Project Portfolio Management (2)
  • Week 07: Policy Documents & Video (6)
  • Week 08: IT Services & Quality (2)
  • Week 09: IT Outsourcing & Cloud Computing (2)
  • Week 10: Monitoring & Evaluating IT (2)
  • Week 11: IT Risk (2)
  • Week 12: IT Security (3)
  • Week 13: Disaster Recovery & Business Continuity (1)
  • Week 14: Regulations, Standards, and Maturity Models (4)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in