Cardiff Metropolitan University
Cardiff School of Technologies
Academic Year: 2023/2024
Term: 2
Module Name: Information Security
Module Code: CIS7028
Module Leader: Dr Liqaa Nawaf
MSc Programme: M.Sc Data Science
Assignment Title: REVIEW OF CYBER-ATTACKS AND INFORMATION SECURITY FOR BUSINESS
Student Name:
AYENI, IRIA IMONIKHE
Student ID:
ST20229033
Feedback:
Signature:
Date:
Contents
INTRODUCTION ....................................................................................................................................... 4
AIMS AND OBJECTIVES ............................................................................................................................ 4
MARRIOT HOTEL DATA BREACH 2022 .................................................................................................... 5
DESCRIPTION OF ATTACK .................................................................................................................... 5
Defining Social Engineering. ........................................................................................................... 6
VULNERABILITIES EXPOSED................................................................................................................. 7
LOSS TO THE ORGANISATION ............................................................................................................. 7
HOW THE ATTACK WAS MANIFESTED AND TOOLS USED ................................................................... 9
PREVENTION MECHANISM OF THE MARRIOTT DATA BREACH ........................................................ 10
Train Employees on Social Engineering ........................................................................................ 10
Set up Suspicious Activity Alerts ................................................................................................... 10
Employ Zero Trust Architecture .................................................................................................... 10
Learn from Past Attacks ................................................................................................................ 10
TASK 2: ISO27001 .................................................................................................................................. 11
INTRODUCTION ................................................................................................................................. 11
TASK 2.1a: ALTERNATIVES TO ISO 27001 .......................................................................................... 11
NIST Cyber security Framework: ................................................................................................... 11
COBIT framework: ......................................................................................................................... 11
ITIL framework .............................................................................................................................. 11
Cyber Essentials Plus ..................................................................................................................... 11
SOC 2 standard: ............................................................................................................................. 12
TASK 2.1b: Wider Benefits of ISO27001 to Access Bank Plc ............................................................. 12
Increased trust and credibility ...................................................................................................... 12
Improved risk management .......................................................................................................... 12
Regulatory compliance ................................................................................................................. 12
Competitive advantage: ................................................................................................................ 12
Better internal processes .............................................................................................................. 12
Improved customer relationships ................................................................................................. 12
TASK 2.2.1: ISO 27001 Main Clauses ................................................................................................. 12
Context of the organization .......................................................................................................... 12
Leadership: .................................................................................................................................... 12
Planning: ....................................................................................................................................... 13
Support: ........................................................................................................................................ 13
Operation: ..................................................................................................................................... 13
Performance evaluation................................................................................................................ 13
Clause 10 of ISO 27001 - Improvement ........................................................................................ 13
TASK 2.2.2: SECURITY CONTROL OBJECTIVES APPLICABLE FOR THE CHOSEN COMPANY ................ 13
Information Security Policies: ....................................................................................................... 13
Organisation of information security ............................................................................................ 13
Human resource security .............................................................................................................. 13
Asset management: ...................................................................................................................... 13
Access control ............................................................................................................................... 13
Cryptography ................................................................................................................................ 13
Physical and environmental security ............................................................................................ 14
Operations security ....................................................................................................................... 14
Communications security.............................................................................................................. 14
System acquisition, development and maintenance .................................................................... 14
Supplier relationships ................................................................................................................... 14
Information security incident management ................................................................................. 14
Information security aspects of business continuity management .............................................. 14
Compliance: .................................................................................................................................. 14
TASK 2.2.3: AUDITING AND CERTIFICATION PROCESS OF ISO27001 ................................................ 14
Create A Project Plan .................................................................................................................... 14
Define The Scope f your ISMS ....................................................................................................... 14
Perform a Risk Assessment and Gap Analysis ............................................................................... 14
Design and Implement Policies And Controls ............................................................................... 14
Employee Education and Training ................................................................................................ 15
Document Presentation ................................................................................................................ 15
External Certification Audit ........................................................................................................... 15
TASK 3: DATA DISCOVERY, CLASSIFICATION, PROCESSING, LOSS PREVENTION AND PRIVACY
ENHANCEMENT ..................................................................................................................................... 16
3.1: Data Protection by Design and Default...................................................................................... 16
3.2: MECHANISM TO IMPLEMENT DATA PROTECTION BY DESIGN AND DEFAULT .......................... 16
DATA DISCOVERY .............................................................................................................................. 16
Data classification ............................................................................................................................. 17
Data Processing Impact Assessment (DPIA): .................................................................................... 17
Data Loss Prevention (DLP): .............................................................................................................. 17
Mechanism and privacy-enhancing technology (PET): ..................................................................... 18
REFERENCES .......................................................................................................................................... 18
INTRODUCTION
Data and information security are the very foundation of a nation, organisation, or company. The
effects of data and information breaches to an organisation could be enormous; it can lean lead to
huge monetary losses, reputational and brand damage, complete bankruptcy and many more. For an
individual, a data breach can cause fraud, identity theft, and financial losses, among others. The
European Union (2016) defines a data breach as a compromise of information leading to access to
protected data, loss of sensitive data, alteration, unauthorised disclosure of information.
There are many causes of data and information loss; they include cyber-attacks, stolen credentials,
application vulnerabilities, social engineering, and employee negligence. Cybercriminals continue to
expand their methods and operations, using different variety of tactics. These include social
engineering, malware, and ransom ware.
It is my duty as a cyber-security consultant to identify and mitigate against possible threats,
vulnerabilities, and attacks on the data and information systems of a firm, organisation, or nation.
AIMS AND OBJECTIVES
The aim of this paper is to do a critical review of cyber-attacks and information security for business.
1. To review the tools of cyber attacks
2. To examine GDPR and its role in cybersecurity for business
3. To proffer solutions to possible lapses in customer’s information security Management
systems
MARRIOT HOTEL DATA BREACH 2022
Marriott International was founded in 1927 by the then-newlywed couple, Willard and Alice Marriott.
The company started as a root beer stand. The company grew in leaps and bounds and made a shift
into the hotel business in 1957 with J. Willard Marriott’s son, Bill, as CEO (Marriott, 2022; Carly, 2022).
The company has experienced tremendous growth, acquiring major brands in the hospitality industry,
acquiring top franchises, and expanding its business presence to over 556 locations (as of 2020) all
over the world. In the trail of this growth and expansion have been the dark shadows of cyber security
attacks and data breaches, with their fangs of lawsuits, sanctions, and payouts in millions of dollars
and pounds. (Marriot, 2022).
Marriott Hotels' conglomerate woes with cyber security attacks started in 2018. This was an inherited
attack from a firm, Starwood Hotels Group, which Marriot bought in 2015. The data breach was
noticed years later, in 2018. They were fined 18.4 million pounds by the General Data Protection
Regulation, after the GDPR adjudged them to have failed to devise effective measures to protect
people's data. There was another data breach in 2020 and yet another in 202 (Carly, 2022).
DESCRIPTION OF ATTACK
Carly (2022) reported that In June 2022, the Marriott hotel was attack when certain cyber-criminal
group targeted the hotel and used social engineering tool to deceive an employee and gained access
into a server at the Marriott hotel at Baltimore-Washington International Airport in Maryland and
stealing passwords, which they then used to gain access their internal database.
The black hat team of hackers attempted to extort money from Marriott, which Marriot did not pay.
The hackers, however, made out with 20 gigabytes of sensitive customer data, including credit card
details and personal information of staff and customers. The tool used was social engineering.
Defining Social Engineering.
Social Engineering Life Cycle
Available at: https://www.imperva.com/learn/application-security/social-engineering-
attack/#:~:text=Social%20engineering%20is%20the%20term,in%20one%20or%20more%20steps.
The term "social engineering" is used to describe a wide range of malevolent behaviours carried out
through interactions with other people. Users are duped into divulging critical information or
committing security blunders through psychological manipulation. (Erez, 2021).
Social engineering is an entirely non-technical method for a hacker to get details about a target.
Attacks that use social engineering try to persuade people to take certain activities or reveal sensitive
information.
Social engineering attacks can involve many steps. To prepare for an attack, the criminal first probes
the target for background information as entry points and lapse in security measures. Next, the
attacker tries to gain the trust of the victim and provide incentives for further breaching activities,
such as disclosure of confidential information or access to critical resources. (Erec, 2021)
In addition to preying on people's vulnerabilities, social engineers frequently rely on people's
willingness to be helpful. A few examples of social engineering attacks are as follows:
Pretexting - This involves a hacker calling an individual and lying to them in an attempt to gain access
to sensitive data.
Something for Something (Quid pro quo) - This is when a hacker requests personal information from
an individual in exchange for a gift.
VULNERABILITIES EXPOSED
The vulnerability exposed include the following
1. Lack of Adequate Social Engineering Training: Spotting social engineering attacks could be
challenging, but employee training can help to curtail it. In the cause of training, it is proper
to give them examples social engineering techniques and show them ways to defend against
them. This would give them the ability to identify and avoid possible attacks.
2. Lack of Training on Password Complexity: It is important to teach employees about the
importance of a strong password, Marriot obviously did not do this
3. Lack of Multifactor Authentication: This is important for large and small organisation
4. Lack of data classification: A staff unlearned about cyber security should have restricted access
to sensitive information
5. Lack of internal audit security control: A lack of sufficient security measures might increase
the chances of a data breach
LOSS TO THE ORGANISATION
Databreaches.net received confirmation from Marriott and the red hat hackers that the hotel did not
comply with any monetary demand. But from the 20 GB of material that they had stolen, the hackers
gave DataBreaches.net samples. Several of the sample's files contained private and confidential
information from internal business documents. Other documents, aside from internal business
paperwork, contained data about hotel workers and visitors. Several documents where airlines made
lodging arrangements for their flight crews at BWIA were examined by DataBreaches. The forms listed
the crew members' names, first initials, last names, the flight numbers they would be travelling on
and off of as well as their positions (pilot or flight attendant), as well as the rooms they would be
staying in ((Vigliarolo B, 2022; Josh F.2023).).
The group that claimed responsibility for the attack also said the stolen data included guest credit card
details and confidential information about both guests and staff. Examples of the data provided to
Databreaches.net show reservation logs of airline crew and guest names and other information, as
well as personal and corporate credit card information used for reservations, payroll, personal
employee and hotel information, as of January 2022. . and even the evaluation of the employee of the
hotel employee (Vigliarolo B, 2022; Josh F.2023).
Fig 1: information on hotel guests and full corporate credit card numbers with CVV and expiration
date
Source: Vigliarolo (2022).
It is certain that these are not what an organisation would want leaked. Marriot said that it will inform
300-400 individuals regarding the incident, and has already notified appropriate regulatory agencies.
This is not the first time Marriott has suffered a significant data breach. Hackers breached the hotel
chain in 2014 to access almost 340 million guest records worldwide an incident that went
undetected until September 2018 and led to a £14.4 million ($24 million) fine from the U.K.’s
Information Commissioner’s Office. In January 2020, Marriott was hacked again in a separate incident
that affected around 5.2 million guests (Vigliarolo, B., 2022).
HOW THE ATTACK WAS MANIFESTED AND TOOLS USED
Marriott got to know that they have been hacked when a security tool flagged an unusual database
query. The database query was made by a user with administrator privileges, but analysis quickly
revealed that the person to whom that account was assigned was not the one who made the query;
someone else had managed to take control of account through social engineering (Carly, 2022)
According to Carly (2022) Investigators began scouring the system for clues, and discovered a Remote
Access Trojan (RAT) along with MimiKatz, a tool for sniffing out username/password combos in system
memory. Together, these two tools could have given the attackers control of the administrator
account. Remote Access Trojans (RAT) is often downloaded from phishing emails. A Remote Access
Trojan (RAT) is a type of malware that allows hackers to monitor and control a computer or network
Carly (2022) reveal that a RAT is a type of malware that’s very similar to legitimate remote access
programs. The main difference is that RATs are installed on a computer without a user’s knowledge.
Most legitimate remote access programs are made for tech support and file sharing purposes, while
RATs are made for spying on, hijacking, or destroying computers.
PREVENTION MECHANISM OF THE MARRIOTT DATA BREACH
Information security professionals and managers of conglomerate might begin to identify weaknesses
in their own systems by studying Marriott woes with data breaches ..
Train Employees on Social Engineering
Cybercriminals used social engineering to enter the internal system of the 2022 Marriott hack. This
well-known technique is used by criminals to manipulate employees into giving out private
information (Dissent, 2022). It is important to train employees at regular interval to identify red flags
of social engineering.
Set up Suspicious Activity Alerts
In the latest Marriott hack, Marriott's IT managers were caught off guard by the blackmail attempt
because they were notified of the hack almost immediately after it happened. They then
communicated with the hackers in an attempt to reach an agreement, although they did not pay the
ransom (Dissent, 2022)
They were able to take advantage of the situation because they were immediately notified of the
unauthorized query.
Employ Zero Trust Architecture
When we make our system to authenticate every stage of a communication, we can identify
suspicious activity much earlier and quarantine it before it causes damage. (Dissent, 2022)
Learn from Past Attacks
If your business is unfortunate enough to be the target of a data breach, it is important to learn from
the experience and implement more effective safeguards. As Marriott saw, being the victim of a data
breach puts you at additional risk of future hacking attempts. If you've been beaten once, there's a
good chance you'll be beaten again (Dissent, 2022).
TASK 2: ISO27001
INTRODUCTION
Access Bank Plc is a household name in the finance industry. It has it headquarters in Nigeria
with branches in the United Kingdom The importance of data protection in a finance firm
cannot be over emphasized. Our firm is currently expanding it frontiers, and our database and
server is growing in huge proportions, it is our collectively responsibility to protect this data
from misuse and unauthorized access.
The ISO 27001 standards are an example of Information Security Management Standards
which many firms, government have adopted to keep-ff cyber criminals. The ISO 27001
standards provide a springboard for implementing cyber security apparatus within an
organization. As my chief information officer already knows the ISO 270001 help us
continually improve the information security management system of our bank and give us the
confidentiality and security of a tier one bank.
TASK 2.1a: ALTERNATIVES TO ISO 27001
The ISO 27001 is the most widely accepted and recognized standard for information security
management, but there are several alternatives to 1SO 27001.
NIST Cyber security Framework: The National Institute of Standards and Technology (NIST)
published this framework, which offers recommendations for enhancing cybersecurity risk
management and resilience. Organisations in the United States use it extensively, and it is
rising in popularity worldwide (Karen,2022).
COBIT framework: This framework provides a set of procedures, controls, and best practices for
managing information technology operations and might be used by Access Bank to align their
information technology goals with our overall business goals (Ingrid, 2022). According to John
(2015) Control Objectives for Information and Related Technology, COBIT, is an information
technology governance and management framework created by ISACA (Information Systems
Audit and Control Association).
ITIL framework: The framework is developed to assist organizations align their information
technology services with their business needs, and it provides a set of processes, procedures,
and roles for managing IT services throughout the business lifecycle. It helps Access bank
align services with customers' needs, and produce a clear model for ongoing success of a
business. This framework was developed by AXELOS and its latest edition ITIL 4 - was
launched in 2019 (Karen,2022).
Cyber Essentials Plus: This is a cybersecurity certification scheme developed by the UK government to
assist organizations of different sizes and types improve their cybersecurity position.). Cyber Essentials
plus is the highest level of certification offered under the Cyber Essentials scheme and It is managed
by the NCSC (National Cyber Security Centre. The certification is awarded to organizations that
demonstrate compliance with a set of technical controls that are designed to protect against common
cyber threats (Infosec, 2023)
SOC 2 standard: This was developed by The American Institute of Certified Public Accountants
(AICPA). Service Organisation Control 2 offers recommendations for auditing and reporting on the
security, availability, processing integrity, confidentiality, and privacy of information processed by
service organisations. The standard is designed to help service organizations demonstrate their
commitment to information security and privacy (Lincoln, 2020; John, 2023)
TASK 2.1b: Wider Benefits of ISO27001 to Access Bank Plc
An organisation can get a number of advantages by implementing ISO 27001 and obtaining
certification, including:
Increased trust and credibility: The accomplishment of ISO 27001 certification shows
stakeholders that a company takes information security seriously and has put in place reliable
controls to protect sensitive data.
Improved risk management: ISO 27001 requires enterprises to assess risks to their information
assets and adopt controls to reduce those risks. The probability of data breaches and other
security incidents can be decreased with the help of this strategy.
Regulatory compliance: Information security legal and regulatory obligations, such as the EU
General Data Protection Regulation (GDPR) and other data protection legislation, can be met
by Access Bank with the use of ISO 27001.
Competitive advantage: Achieving ISO 27001 certification can give a business a competitive
advantage by proving its commitment to information security and giving it an edge over
competitors that do not have certification.
Better internal processes: Implementing ISO 27001 can help organizations streamline their
information security processes and improve communication and collaboration across
different departments.
Improved customer relationships: Customers are increasingly concerned about the security of
their data and are more likely to do business with organizations that can demonstrate robust
information security practices.
TASK 2.2.1: ISO 27001 Main Clauses
According to Dejan (2021) the official ISO 27001 standards has several clauses, and
appendices called annexes. The clauses important to Access Bank are clauses 4-10, these
clauses spell out the information security management system
Context of the organization: This clause concerns itself with internal and external problems, as well
as interested parties that should be found and taken into account. For Example regulatory
concerns and others (Dejan, 2021)
Leadership: This clause requires Access Bank to have adequate leadership. There must be a
commitment of the top management to the objectives establishing our bank. Management
must provide resources as well as supporting persons, leaders and teams for the ISMS. In
addition, management needs to put in place a top-level policy for information security
(Dejan, 2021).
Planning: This section requires businesses to establish, implement, maintain, and continuously
enhance their information security management systems while also carefully considering
risks and opportunities. (Dejan , 2021)
Support: This relates to competence of employees, infrastructure, resources, communication and
effective documentation need of ISMS (Dejan, 2021)
Operation: This clause outlines the processes, execution of risk assessments and the corresponding
treatment to manage identified risks. (Dejan, 2021)
Performance evaluation: The monitoring, measurement, analysis, and evaluation of the
information security management system are covered by this clause of the ISO 27001
standard. Access Bank must also carry out internal audits. (Dejan 2021)
Clause 10 of ISO 27001 - Improvement Clause 10 is a follow-up to clause 9. It requires addressing
nonconformities, implementing corrective measure and implementing a regular
improvement mechanism (Dejan, 2021)
TASK 2.2.2: SECURITY CONTROL OBJECTIVES APPLICABLE FOR THE CHOSEN COMPANY
ISO 27001 has a set of 14 security control objectives that Access Bank can use as a basis for
implementing their information security management system (ISMS). These security control
objectives are 91 in number and divided into 14 categories
Information Security Policies: This category relates to the objectives of establishing and
maintaining an information security policy for the organization (Luke, 2023).
Organisation of information security . The objectives in this category relates to the management
structure of the organization's information security program. It concerns the assignment of
responsibilities (Luke, 2023).
Human resource security: This relates to security of personnel, such as background checks and
security awareness training (Luke, 2023).
Asset management: Controls objectives pertaining to the inventory and categorization of
information assets fall under this category (Luke, 2023).
Access control: This category includes controls related to managing access to the organization's
information systems and data. Employers can only view information that directly concerns
their job( Luke, 2023).
Cryptography: Data encryption and the management of sensitive information are the topics
covered in this area. It guarantees that businesses employ cryptography to preserve the
availability, confidentiality, and integrity of data (Luke, 2023).
Physical and environmental security: This control category relates to the physical security of the
organization's facilities and equipment. That is, protection of premises and sensitive data
from unauthorized access, damage, or interference, and preventing the loss, damage or theft
of an organisation’s information asset containers (Luke, 2023).
Operations security: Controls for managing the organization's information systems, like change
of management and backup procedures are contained in this category.
Communications security: This deals to the way firms safeguard the information in networks,
guaranteeing that the confidentiality, integrity and availability of information in those
networks.
System acquisition, development and maintenance: this category ensures that information security
remains a central part of the organisation’s processes across the entire lifecycle (Luke, 2023).
Supplier relationships: This annex concerns the contractual agreements organisations have with
third parties (Luke, 2023).
Information security incident management : This annex is about how to manage and report
security incidents. It requires organisations to designate certain employees to handle tasks,
ensuring that incident response is managed consistently. (Luke, 2023).
Information security aspects of business continuity management: This category's goal is to develop
a successful system for handling business disruptions. It’s broken into two portions. (Luke,
2023).
Compliance: By assisting Access Bank in comprehending their contractual and legal obligations,
this reduces their risk of non-compliance and the associated fines. (Luke, 2023).
TASK 2.2.3: AUDITING AND CERTIFICATION PROCESS OF ISO27001
According to Karaev (2022) certification and auditing process of ISO 27001 typically involves
the following phases:
Create A Project Plan
This phase concerns an articulation of the process, personnel, resources and training that will
be require to achieve the ISO27001 certification
Define The Scope f your ISMS
This phase requires Access Bank to identify the type of data it needs to protect, who can view
what data and what data and aspect of the business the certificate will generally cover
Perform a Risk Assessment and Gap Analysis
In this phase, the organization's current information security management system (ISMS) will
be compared to the requirements of ISO 27001.
Design and Implement Policies And Controls
Having identified the gaps and risk, this phase involves deciding which risk to address and
which to tolerate
Employee Education and Training
ISO 27001 requires all staff to be trained about information security. This makes certain that everyone
working for Access Bank is aware of the value of data security and their part in achieving and
maintaining compliance. (Karaev, 2022).
Document Presentation
To obtain ISO 27001 certification, Access Bank MUST demonstrate to the auditor that we have
implemented efficient policies and controls and that they are operating in accordance with
the standard. (Karaev, 2022).
External Certification Audit
This phase requires an external auditor to evaluate our ISMS to ascertain that it meets the
requirements for ISO 27001 certification.
There are two stages to this; First, they will review our ISMS documentation to confirm that
we have the right policies and procedures.
Secondly, they will review our business processes and security controls. When both statges
are complete and okay, we will issued an ISO 27001 certification that is valid for three years.
(Karaev, 2022).
.
TASK 3: DATA DISCOVERY, CLASSIFICATION, PROCESSING, LOSS
PREVENTION AND PRIVACY ENHANCEMENT
3.1: Data Protection by Design and Default
In order to implement the data protection principles and incorporate safeguards into our data
processing, we must put in place the necessary technological and organisational measures,
according to the UK GDPR.
Pseudonymization is a technique used in data protection by design, which involves swapping
out personally identifying information for made-up identifiers. Additionally, encryption is
used, which encrypts messages so that only authorised parties may decipher them (European
Commission, 2016.)
Access Bank is required under data protection by default to make sure that we only process
the data required to fulfil stated purpose. In order to prevent personal data from being
automatically made accessible to an unlimited number of people, it is important that personal
data be processed with the maximum privacy protection (for example, just the data necessary
should be processed, short storage time, limited accessibility). It builds on the fundamental
data protection principles of data minimization and purpose limitation (European
Commission, 2016.)
3.2: MECHANISM TO IMPLEMENT DATA PROTECTION BY DESIGN AND DEFAULT.
Access Bank is a service industry it needs the personal data of its customer to design
customer-centric products and services. It is the banks duty to safeguard this personal data
against loss, breach, and unauthorized access.
With our presence in the UK we must abide by certain rules established by the GDPR in order
to protect the privacy of our customers. These mechanisms that will help Access Bank protect
customers data as established by the GDPR are discussed in this section.
DATA DISCOVERY
Data discovery is a crucial tool for Access Bank to use to comprehend how they store, process,
maintain, and transfer personal data as well as to make sure they put the right organisational
safeguards in place to protect themselves and adhere to the General Data Protection
Regulation (GDPR). The gathering and study of information from various sources in order to
gain insight from veiled patterns and examples is known as data discovery or information
revelation. Data discovery gives a company the know-how, the tools, and the capacity to
examine data sources and derive insightful conclusions. It enables an enterprise to alter
disorderly and unstructured data to support and improve its analysis. Data discovery can be
carried either manually or electronically.
Data classification
All of the data in a database must be identified and categorised into certain types according
to their associated risk value. For instance, the GDPR classifies information like a British
resident's home address and contact information as PII (Ryan, 2022)
According to Ryan (2022) data can be categorised in a variety of ways, and classification
involves grouping data into predetermined categories that correspond to various data kinds.
Ryan grouped data in to public data, confidential data sensitive data and personal data.
Organisations are required under GDPR to safeguard customer data and make sure that the
necessary security measures are in place. Organisations can organise their stored data
depending on perceived risk via data categorization, and then take appropriate action. Public
data, internal data, secret data, and restricted data are the four categories of data used in the
GDPR (Ryan, 2022).
Data Processing Impact Assessment (DPIA):
The purpose of a data protection impact assessment (DPIA) is to help organisations identify,
analyse, and minimise privacy risks associated with user data collection, processing, usage,
storage, and sharing. It's one of the essential elements needed to adhere to the GDPR. (Osano,
2022)
Data Loss Prevention (DLP):
DLP can be used by Access Bank Plc to detect data loss, prevent unauthorised data transfers outside
the organisation, and prevent the destruction of sensitive or personally identifiable information (PII).
It is also used to help businesses with data security and ensure they comply with regulations including
the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation, and the
Health Insurance Portability and Accountability Act (HIPAA). Although the terms "data loss" and "data
leakage prevention" are occasionally used synonymously, corporations can safeguard themselves
from both with DLP protection. Locating sensitive information on multiple local and cloud-based
platforms is made possible by DLP. Stop accidental data sharing, Keep an eye on and protect data,
Explain to folks how to keep up with compliance
Mechanism and privacy-enhancing technology (PET):
privacy enhancing technologies are tools that guarantee privacy during data processing or
sharing. The PET must be viewed as enablers for utilising data to create value while adhering
to the GDPR (Eura, 2022).
REFERENCES
Carly, P. (2022): “Hotel giant Marriott confirms yet another data breach”. https://techcrunch.com/
Dejan, K. (2021)."What is ISO 27001? A brief introduction to the information security
management standard," Advisera, 2021. [Online]. Available:
https://advisera.com/27001academy/what-is-iso-27001/. [Accessed: 17-May-2023].
Dissent, D. (2022): “EXCLUSIVE: Marriott hacked again? Yes. Here’s what we know”. Databreaches.net
Erez H. (2021). Social Engineering Attack: How to Identify and Avoid Social Engineering. Retrieved May
12, 2023, from https://www.imperva.com/learn/application-security/social-engineering-
attack/#:~:text=Social%20engineering%20is%20the%20term,in%20one%20or%20more%20steps.
Eura, N. (2022). Privacy-enhancing technologies 2022: A summary. Retrieved from
https://research.euranova.eu/2022/05/10/privacy-enhancing-technologies-2022-a-
summary/#:~:text=Privacy%20Enhancing%20Technologies%20are%20the%20set%20of%20t
ools,Differential%20privacy%20or%20anonymisation%2C%20and%20synthetic%20data%20
generation. Accessed 10/05/2023
European Union. (2016). Data protection guidance question 11. Retrieved May 11, 2023, from
https://europa.eu/citizens-initiative/data-protection-guidance-question-
11_en#:~:text=A%20personal%20data%20breach%20means%20a%20breach%20of,access%20to%2C
%20personal%20data%20transmitted%2C%20stored%20or%20processed
European Commission. (2016.) What does data protection by design and default mean?. Available at:
https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-
organisations/obligations/what-does-data-protection-design-and-default-mean_en. Accessed on:
2023-05-11.
European Union. (2016). General Data Protection Regulation. Official Journal of the European Union.
Available at: https://eur-lex.europa.eu/legal-
content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN [Accessed 10 May 2023].
Infosec Partners (2023). Cyber Essentials Plus. [online] Available at:
https://www.infosecpartners.com/cyber-security-testing-and-compliance/cyber-essentials-
plus [Accessed 6 May 2023].
Ingrid Horvath (2022). What is COBIT 5 Framework? [online] Available
at:https://www.invensislearning.com/blog/what-is-cobit-5-framework/ [Accessed 6 May
2023].
John, F.(2015). Leveraging COBIT to Implement Information Security. [online] Available at:
https://www.isaca.org/resources/news-and-trends/industry-news/2015/leveraging-cobit-
to-implement-information-security [Accessed 6 May 2023].
John, S. (2023). What is SOC 2? Available at: https://secureframe.com/hub/soc-2/what-is-soc-2
[Accessed 10 May 2023].
Josh F. (2023). Marriott data breach FAQ: How did it happen and what was the impact?. IDG
Communications, Inc.
Karaev, K. (2022). ISO 27001 Certification Process: Steps to Getting Certified. Secureframe.
Available at: https://secureframe.com/hub/iso-27001/certification-process/ [Accessed 12
May 2023].
Karen A. Scarfone, Daniel R. Benigni, Timothy Grance. (2022). Cyber Security Standards.
Available at: https://www.nist.gov/publications/cyber-security-standards [Accessed 10 May
2023].
Lincoln, P. (2020). SOC 2 Compliance. Available at: https://www.vanta.com/landing/soc-2
[Accessed 10 May 2023].
Luke I. (2023). ISO 27001: The 14 control sets of Annex A explained. [online] Available at:
https://www.itgovernance.co.uk/blog/iso-27001-the-14-control-sets-of-annex-a-explained
[Accessed 10 May 2023].
Michael, N (2022.). What is the ITIL Framework? [online] Available at:
https://www.diligent.com/insights/compliance/what-is-the-itil-framework/ [Accessed 6 May
2023].
Patrice, P (2022). DLP (Data Loss Prevention). Retrieved from
https://www.fortinet.com/resources/cyberglossary/dlp
Osano, S (2022). DPIA: Data Protection Impact Assessments. Osano. Retrieved from
https://www.osano.com/articles/dpia-data-protection-impact-
assessments#:~:text=A%20data%20protection%20impact%20assessment%20(DPIA)%20is%
20a,key%20components%20required%20to%20comply%20with%20the%20GDPR. [Accessed
on 11 May 2023].
Ryan o (2022) . GDPR Data Classification: How to Classify Sensitive Data Under GDPR.
[Online].Availableat:https://securiti.ai/blog/gdpr-data-
classification/#:~:text=Data%20classification%20involves%20identifying%20and%20categori
zing%20all%20data,resident%20are%20classified%20as%20PII%20per%20the%20GDPR.
[Accessed: 10 May, 2023].
Seersco. (n.d.). What is data discovery and why it is important? Seersco. Available at:
https://seersco.com/articles/what-is-data-discovery-and-why-it-is-
important/#:~:text=Data%20discovery%20is%20also%20an%20important%20technique%20
to,comply%20with%20the%20General%20Data%20Protection%20Regulation%20%28GDPR
%29. Accessed on: [insert date accessed].
Vigliarolo, Brandon (July 6, 2022). "Marriott Hotels admits to third data breach in 4 years". The
Register. The Register. Retrieved June 7, 2022.