To gain access to online services, the newly adopted “cybersecurity” policy requires users to establish a user profile that includes password recovery information The user profile registration form requires name, address, cell phone number, email address, date of birth, and the last four digits of the individual’s social security number. Setting up the password recovery section of the profile requires uses to provide answers to challenge questions that include disclosure of private information about the individual’s immediate and extended family members (names, birth places, schools, etc.).
Your “Expert Opinion” (document) should address the following issues:
How can the local government officials convince residents that this “invasion of privacy” (collection of personal information during account registration) is necessary and for their benefits?
Should the local government suspend implementation of the new policy for 90 days (180 days?) to allow members of the public to comment on the new policy? Why or Why not?
Identify and discuss an alternative to challenge questions as a means of authentication for the password recovery/reset process.
Provide in-text citations and references for 3 or more authoritative sources. Put the reference list at the end of your posting.
Resources:
https://www.policynl.ca/policydevelopment/policycycle.html
https://www.iacdautomate.org/aboutiacd
https://us-cert.cisa.gov/sites/default/files/ncirp/National_Cyber_Incident_Response_Plan.pdf