Introduction

Privacy is not something to take for granted as true privacy becomes increasingly challenging to find. In most day-to-day cases, you are aware that your information is being collected. As you drive, video surveillance monitors for traffic conditions. When you purchase items with credit cards, your buying history is analyzed for marketing. As you use the Internet at work, your browsing habits might be monitored for performance. These are known impacts on personal privacy, but there are many other examples where your privacy is lost without your knowledge or consent.

The loss of privacy data has implications for both the individual(s) responsible and the organization at which the individual(s) works. Privacy and information systems security can be violated, but breaches can also be prevented.

Instruction

In this lab, you will review a real-world case study that involves the loss of privacy information, and you will analyze what violations occurred, the implications of those violations, and the possible mitigation remedies that can prevent future violations.

Read and review “VA Ignores Cybersecurity Warnings https://www.pcworld.com/article/126093/article.html. ” by Grant Gross. Analyze what violations occurred, the implications of those violations, and the possible mitigation remedies that can prevent future violations.

Related Document:

Executive Summary of Case Study on U.S. Veterans Affairs and loss of privacy information

The U.S. Department of Veterans Affairs had a privacy data breach in 2006 that an agency employee said affected the records of 26.5 million veterans and their spouses. An employee at the agency reported the breach and said that a laptop he used at his home in Montgomery County, Maryland, had been stolen. This employee had been taking home a laptop that contained private information of the approximately 26.5 million veterans. This privacy information included the veterans’ names, Social Security numbers, the dates of birth, and disability ratings.

On May 17, 2006, the Federal Bureau of Investigation (FBI) was informed of the breach, and it began an investigation along with the Veterans Affairs (VA) Inspector General’s Office. During the investigation, it was discovered that more than the originally reported veterans and their spouses were affected by the theft. In fact, approximately 1.1 million active-duty military personnel were affected, as well as 430,000 members of the National Guard and 645,000 members of the Reserves. In addition, the investigation revealed other information, including:

  • On May 3, 2006, the theft occurred. The employee whose laptop was stolen reported the theft to his supervisors at the agency and to the Maryland police.
  • On May 16, 2006, Veterans Affairs Secretary R. James Nicholson was told of the breach that resulted in unencrypted data being stolen. Supervisors at the agency knew of the theft on May 3 when it happened, but they failed to tell Mr. Nicholson until the May 16 date.
  • On May 22, 2006, the agency finally informed those who were affected by the breach. The agency announced that the laptop had been stolen. The agency reported that the information stolen included veterans’ and their spouses’ names, Social Security numbers, birth dates, and disability ratings. The agency said that the information did not include financial data or electronic health records.
  • The analyst who took the laptop home had been given permission to use the laptop at home. (The agency did not reveal this until after it had already said that the employee was fired for taking the laptop home.) The employee said that he had taken the laptop home regularly for three years.

Congress held a hearing on May 25, 2006. During this hearing, Secretary Nicholson admitted that the stolen information included disability ratings for 2.6 million people.

On June 3, the agency admitted that approximately 50,000 active-duty personnel were also affected by the stolen data. By June 6, 2006, the agency had admitted that approximately 1.1 million active-duty military personnel were affected, as well as 430,000 members of the National Guard and 645,000 members of the Reserves.

On June 29, 2006, an unidentified person turned the laptop over to the agency, which believes it will cost $100 million to $500 million to cover the data theft losses and prevent additional losses.

Calculating Costs;

The concluding paragraph of this case study shows how difficult it can be to calculate the consequences of a crime. Violating data privacy is no exception. The range of $100 million to $500 million is by a factor of five! Why is the total so unclear?

Some costs directly relate to recovery from the crime, while other costs come from closing the vulnerabilities that allowed the crime to happen. The latter helps prevent the same crime from occurring again. It’s easy for someone to simply decide the vulnerabilities should have been closed earlier, saving the recovery costs.

Of course, it’s not that simple in real life. Without the gift of hindsight, costs are far less justified before a disaster than after. The powers that be will resist spending funds on any risk except the most probable and with the most serious consequences. It’s not feasible to mitigate all identified risks, let alone identify and assess the unforeseen ones before they occur. So, some closure doesn’t happen until after a risk presents itself in the worst way.

Still, why so different an estimate of consequential costs? The easier costs include money spent to fix the problem, appease those affected, and estimated losses from downtime. Those directly relate to the crime and are fairly quantifiable. Then additional costs stem from situations that might or might not happen, for example, identity theft and any resulting fraud. No one can calculate for certain that X percentage of the personnel will experience identity theft, or find out years later of a fraudulent loan. The guesswork involved helps broaden the costs, even if by a factor of five.

Deliverables:

In your Lab Report File, you will discuss the case study and answer each of the following questions:

What laws have been violated?
What do you think contributed to the problems that could lead to a violation of these laws?
What are the implications to the individual and organization of these violations?
What are some security controls and mitigation strategies for handling future violations? (Name five to seven.)
If the VA had performed a security and information assurance audit for compliance, what could the VA do on an annual basis to help mitigate this type of loose policy conformance?
How does privacy law differ from information systems security?

Did you know that effective analysis of concepts requires professionalism in handling academic research Papers? Do no compromise on your grade choose professional Research writers at elitetutorslab.com

error: Content is protected !!