find a recent news story that details a breach in information security. The brea
ID: 3874646 • Letter: F
Question
find a recent news story that details a breach in information security. The breach could have occurred in a government organization or in a private company. Give a high-level summary to provide context to your peers (including a link to the article), then, in your posting, include the following:
What kinds of policies would have helped to prevent this breach?
Why would the policies you suggest help the organization?
What can the organization do differently (in regards to information security) to prevent this type of breach in the future?
Explanation / Answer
THE HOME DEPOT DATA BREACH
A massive breach occured for the Hope Depot.Here the attacker made thei way into their POS network and they stole the payment details of the customers.The attackers breached the Home Depot by taking the login details of a third party vendor and then they took the advantage of the zero day vulnerability in Windows to use it for their advantage.Once they were inside they installed some memory scrapping malware.They put the scrapping on nealry 7500 POS terminal and grabbing information of about 56 million credit and debit cards.And by having these information they were able to pull out transactiions at a large amount.
The Home Depot could have installed several security measures so that the breach can be detected and so.First and foremeost they didnt have any secured configuration and protocol for the software and hardware which are present at the POS network.Also there were no regular scanning of the network at the POS environment and also there was no separation between POS and Home Depot main corporate network.Last but not the least they didn't have any control over the third party vendor access and authentication.
The breach at the Home Depot could be prevented by taking proper counter measures.First of all there must be a secure configuration and protocol for the hardware and software which are used at the POS.Secondly they should go for the Point to point encryption for thei payment method which would protect the data.Last but not the least they should separate the network properly from the others.
My opiniion on the wayout which they could have used are
a.Frist and foremost they need to upgrade their POS sysetme.
b.Secondly they should go for Point to point encryption
c.Thirdly all the unneccessary port at the POS devices should be disabled.
d.Fouth of all the USB port must be disabled.
e.Last but not the least the firewall must bu upgraded with all the patches.
In the future to Prevent these breaches the Company should have a good POS devices,SHould follow a point to point encryption and last but not the least the network should be seggregated properly.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.