Really great job. Thank you so much. I really love it. Thank you so much for all of your help.
Target shoppers got an unwelcome holiday surprise in December 2013 when the news came out 40 million Target credit cards had been stolen by accessing data on point of sale (POS) systems. CEO of Target, Gregg Steinhafel, said in an interview that â€œthere was malware installed on our point-of-sale registers.â€ With access to the POS system, the attackers would have access to all track data from customer credit and debit cards. That would expose all of the information encoded on the cardsâ€™ magnetic stripes, giving the attackers full account data customer name, credit card number, CVV number and (if itâ€™s a debit card) the PIN.
Target later revised that number to include private data and announced that up to 70-110 million customers’ data have been compromised. The breach transpired between November 27 and December 15th 2014. Over 11 GB of data was stolen. Target was made aware of this situation in mid-December when the U.S. Department of Justice informed the company that their system was being attacked. Target had received internal notifications prior to this date, but had failed to act.
The problem that impacted up to 110 million Target customers during the holiday shopping season may have been because of an inexpensive â€œoff-the-shelfâ€ malware known as BlackPOS. At a high level, BlackPOS is a â€œvirusâ€ that manipulates the code on the POS device that allows a â€œscreen scrapeâ€ of the data at card swipe. Even with end-to-end encryption, the brief moment in time of swipe to transfer could be captured through the malware code manipulation.
Access to the system came from network credentials that were stolen from an HVAC provider based in Sharpsburg, Penn. Initial speculation was that this vendor was monitoring HVAC systems installed at Target facilities remotely via network connection and that this was the way hackers gained entry into Targets internal network. As it turned out, this was not the case. The compromised data connection was being used for â€œelectronic billing, contract submissions and project managementâ€, not monitoring of equipment. The network credentials were, in fact, gathered after the HVAC contractor’s employee fell victim to a phishing scheme attack and clicked on a malicious email.
Target was not unprepared for the breach. Earlier that year, the company had installed malware detection software by computer security firm FireEye (high-profile FireEye customers include the CIA and Pentagon). The FireEye team in Bangalore, India monitored Targetâ€™s system around the clock, and reported the activity to Targetâ€™s security team based in Minneapolis, Minn.
Exfiltration malware was installed on November 30, 2013 to move the stolen information out of the Target servers. These drop points were first staged around the U.S., then to computers in Russia. It was at this point that the Bangalore team became aware that something was wrong and notified the Target security team in Minneapolis. For reasons that are unclear, Target’s Minneapolis team failed to act on the alert, allowing customer information to be compromised.
The initial reports on this story attracted the attention of many in the construction industry. Although, in this case, access to Target’s credit card system did not come through HVAC unit, that scenario is not an improbable one. Remote monitoring of HVAC equipment is possible and future security incidents are not unlikely.
Target cyber breach is the second biggest retail hack in U.S. history. In the days prior to Thanksgiving 2013, someone installed malware called BlackPOS in Targetâ€™s security and payments system designed to steal every credit card used at the companyâ€™s 1,797 U.S. stores. At the critical momentâ€”when the Christmas gifts had been scanned and bagged and the cashier asked for a swipeâ€”the malware would step in, capture the shopperâ€™s credit card number, and store it on a Target server commandeered by the hackers. After reading this brief information about the Target cyber security breach, please answer the following
1. In your own words, explain what was the main reason for the Target data breach?
2. If you will perform an Audit Plan, describe the most critical areas that should be included in the Audit Universe? how you can priorities between them? (
at least two pages
3. What do you think; did Target have good security measures? Recommend THREE internal controls that should be in place to help Target mitigate any possible breaches in the future?
4. Data center security is of increasing concern, with data breaches and cyber vulnerabilities more and more in the news headlines. Briefly talk about Target’s new datacenters?
Project Instruction And Guidelines:
1. Use APA Format to reference any source of information (User your own words donâ€™t copy)
http://www.hbs.edu/faculty/Pages/item.aspx?num=51339 https://www.solutionary.com/resource-center/blog/2014/01/target-breach-overview/ http://www.zdnet.com/article/anatomy-of-the-target-data-breach-missed-opportunities-andlessons-learned/
Delivering a high-quality product at a reasonable price is not enough anymore.
That’s why we have developed 5 beneficial guarantees that will make your experience with our service enjoyable, easy, and safe.
You have to be 100% sure of the quality of your product to give a money-back guarantee. This describes us perfectly. Make sure that this guarantee is totally transparent.Read more
Each paper is composed from scratch, according to your instructions. It is then checked by our plagiarism-detection software. There is no gap where plagiarism could squeeze in.Read more
Thanks to our free revisions, there is no way for you to be unsatisfied. We will work on your paper until you are completely happy with the result.Read more
Your email is safe, as we store it according to international data protection rules. Your bank details are secure, as we use only reliable payment systems.Read more
By sending us your money, you buy the service we provide. Check out our terms and conditions if you prefer business talks to be laid out in official language.Read more