Computer Security Risk Management and Legal Issues - Uber Data Breach
Verified
Added on 2023/06/03
|3
|840
|149
AI Summary
This discussion is about essential risk management and legal issues related to Uber data breach being one of huge data breaches in the world. Proper planning and security assessments must be carried out to handle the breach better.
Contribute Materials
Your contribution can guide someone’s learning journey. Share your
documents today.
Risk Management2 Risk Management and Legal issues This discussion is about essential risk management and legal issues related to Uber data breach being one of huge data breaches in the world. On time disclosure of the data breach is essential to the consumers and persons whose personal data is breached. A data breach is an act of losing, leaking or stealing any personal information held by an organisation through unauthorised way1. Thus, if a data breach contains personal data of any individual, it must be announced on time so that any serious damage to any of the affected individuals through data breach can be minimized. In this context,Uber the ride-sharing firm covered a huge data breach that affected 57 million drivers andcustomers,whichhasconfirmedbythe company.Inthelate2016,twohackershad unethicallyaccessedUberusers’aswellas drivers’ data which was stored on a third-party cloud-based service used by the company2. The individualsaccessedinformationthrough downloadeddatafilesholdingpersonal information, as follows: Data of Drivers: Driver’s license numbers withtheirnamesofabove6,00,000 drivers of the United States. DataofRiders:Personalinformation includename,emailIDandmobile number of around 57 million Uber-users of allovertheworld,includedabove mentioned number of drivers3. After the breach, Uber did not expose details of the breach and it is still unknown that which nations got affected due to the breach. Still, according to the Bloomberg’s report, those two hackers also accessed Uber’s log-in details to Amazon Web Services(referredasAWS),whichisadata storagecloudcomputingserviceusedbythe companies. Later then the hack, Uber took immediate steps to protectremainingdataandcloseanyfurther unauthorizedaccess.Uberalsorecognizedthe hackers and paid hackers $100,000 for deleting the data which was downloaded during the breach3. Although, post this big hack, Uber adopted high securitymeasurestoconfineaccessovertheir cloud-basedstoragedata.Yet,disclosureor notification to the consumers or the drivers whose data was breached should have done on time rather than concealing the breach information in order to manage company’s reputation. Those individuals could take essential steps to reduce the damage caused by the data breach. In order to handle the breach better, proper planning and security assessments must be carried out. As the hack or data breach could not stop with high data security, hence this should not have covered up by theUberCompany.Companiesarerequiredto disclose details of data breach to the regulators as it has occurred due to company’s own administration and management failures2. Additionally, if it will be disclosed then it will benefit those customers and users whose data is stolen.Moreover, due to recent data breach cases, Australian Government took an initiative to preventlosses ofpersonalinfo and money. According to this step, organizations must reporttheOfficeoftheAustralianInformation Commissionerandallthepersonswhowillbe affected in case personal data is leaked, or stolen. Hence,samekindoflawsandrulesshouldbe implemented in Canada also for the data breach prevention. Accordingtothecomputersecurityandrisk management guidelines, data breach of Uber could have prevented, if threats controlling in order to ensure computer system security of the firm would have done correctly. Moreover, there are many controlling measures that can be adopted to detect, preventandcorrectorganizationonlinesystem threats4.If Uber used to have proper data security and protection measures, anti-malware, antivirus software,andmostimportantly licensed strong firewall system to prevent unauthorized access to the company network, then data breach could have been prevented or handled in a better way. References
Risk Management2 x [1]Ariel Bogle. (2018) Data breaches: If a company has lost your personal info, they now have to tell you. [Online].https://www.abc.net.au/news/science/2018-02-22/-companies-must-inform-consumers- of-data-breaches/9462170 [2]Dara Khosrowshahi. (2017) 2016 Data Security Incident. [Online]. https://www.uber.com/newsroom/2016-data-incident/ [3]Dave Lee. (2017) Uber concealed huge data breach. [Online]. https://www.bbc.co.uk/news/amp/technology-42075306 [4]K.E. Picanso, "Protecting information security under a uniform data breach notification law," Fordham L., no. Rev., p. 355, 2008. x