https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf
Some of the high level findings include:
- Ineffective IT coordination
- Siloed IT and Security organisations
- No accountability
- No clear owner for business, application and systems
- Patch management process breathtakingly flawed
- Vulnerabilities not adequately remediated or tracked
- Lack of hardening standards
- Certificate management process completely flawed
- Insufficient documentation
- Lack of asset inventories
- No network segmentation
No comments:
Post a Comment