Beginning in 2014,malwareinfected the reservation system ofStarwoodHotels, which included Sheraton, W Hotels,Westin, LeMeridien, Four Points by Sheraton, Aloft and St. Regis.Then, in 2016, Marriott...

1 answer below »

Beginning in 2014,malwareinfected the reservation system ofStarwoodHotels, which included Sheraton, W Hotels,Westin, LeMeridien, Four Points by Sheraton, Aloft and St. Regis.Then, in 2016, Marriott Hotels acquiredStarwood. In November 2018, Marriott discovered and revealed the four-year hacking campaign that attackedStarwood'sreservation database.


A total of 383 million guests were eventually determined to have been affected. The data breach related in the theft of names, addresses, phone numbers, credit card information, email addresses, and millions of unencrypted passport numbers.The Data Breach has arguably subjectedStarwoodto legal liability both in the US (data breach and breach notification laws) and in the EU (the EU General Data Protection Regulation —GDPR).


In your initial post, please answer both of the following questions:


1. Choosing either a US state data breach law or the EU GDPR and explain how it applies or has already been applied toStarwoodfor its data security breach.


2. Using your best judgment,what would you recommend to create and maintain an infrastructure that would most robustly and effectively protect against future breaches and the liabilities resulting from those breaches?Include any specifics you may be familiar with such as hardware and software recommendations, compliance with specific US andinternational laws, industry best practices, and any appropriate third-party vendor solutions.

Answered Same DayOct 17, 2021

Answer To: Beginning in 2014,malwareinfected the reservation system ofStarwoodHotels, which included Sheraton,...

Deepti answered on Oct 19 2021
147 Votes
1. EU GDPR is the European Union’s data protection law- General Data Protection Regulation. It lets the data subjects control the way their personal data is processed and enforces certain obligations on organizations that control and process personal data. This regulation came into existence in 2016 and into effect in 2018. The EU GDPR applies to those organizations that collect, store or process personal data of individuals residing in European Union. Starwood Hotels was bought by an American multinational hospitality company Marriott, which processes and controls its client’s personal information. EU GDPR applies to Starwood Data Breach incident since it offers hotel services to EU residents and...
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here