Question

Find AN EXAMPLE of an ORGANIZATION that faced an information systems security issue or crisis. 1)...

Find AN EXAMPLE of an ORGANIZATION that faced an information systems security issue or crisis.

1) How did the organization identify that there was a security problem?

2) What, if any, security infrastructure and policies were in place when the problem occurred?

3) What initial actions were taken to deal with the situation?

4) From a management perspective, what, if any, new organizational policies and procedures did they institute?

5) Were any new security tools and technologies eventually implemented to further safeguard their systems?

6) What was the business impact? How did they recover? Were there any legal ramifications, loss of customers, or damage of reputation?

7) Generally speaking, how can a business determine the value of investing in security and control?

Homework Answers

Answer #1

Target's data breach-
Target is a well known example an organisation facing crisis in information system security, with its IT systems being hacked and exposing personal data of approximately 110 million customers. The company apologized explaining the hacking that took place, through issuing of a statement and posting video with details. They also offered a free checking of credit for the customers that were affected.

At the time Target had firewalls in place and you trying to divide their network through VLAN. They had also expanded the security through collaborating with Fire-Eye that allows to security to detect any malware and NIDS (network intrusion detection system). However, they could not prevent the system from hacking and also could not detect the breach as they did not look into the warnings that were given by the Fire-Eye, the auto-removal function of few of the malware was also turned off, the segmentation of their systems was weak, etc, the name a few.

The initial actions that were taken to deal with the situation had a few problems, namely
The response given by target was given before the officials were completely aware of the cause of the problem and to what extent it had taken place.
This led Target to constantly contradict their statements that were issued.
They did not know the exact number of customers that had their information hacked into before releasing a statement.
Also, the message that was posted to the website of Target from its CEO that was not accumulating a lot of views as the customers were using social media and not the website to interact and present their complaints to the company. After this breach, the CEO at the time resigned from his post.

Target also appointed a new CIO (chief Information Officer) that had a plan to improve the security system by upgrading the insecure of sale machines effective segmentation of the networks all inclusive log analysis setting up of chip and PIN authorized technology for the payment, and a rigid and authoritarian access. Target also stated that they would be spending $100 million to implement a new systems to install new payment methods, setting up of advanced technology such as white-listing, and other security measures secure it's payment system and customer data.

The changing of two statements and not knowing completely about the situation made target look unprofessional and a little suspicious to the customers. Eventually comic the federal judge presented a preliminary show me to $10 million settlement with the shopping that was affected could be each awarded with up to $10,000 in damages.

A business can determine the value of investing in security and control, learning from the mistakes that were made by target in this incident, that include neglecting of the important security alerts that were given to them prior to the breach, weak segmentation of their network, and or not well secured point of sale data handling. The businesses should use superior quality design and better actions should be taken to develop and set up security solutions.

P.S. - leave a comment below is any explanation is needed.

Know the answer?
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for?
Ask your own homework help question
Similar Questions
By doing a search of the Internet or by other research methods, find an example of...
By doing a search of the Internet or by other research methods, find an example of an organization that faced an information systems security issue or crisis. 1) How did the organization identify that there was a security problem? 2) What, if any, security infrastructure and policies were in place when the problem occurred? 3) What initial actions were taken to deal with the situation? 4) From a management perspective, what, if any, new organizational policies and procedures did they...
find an example of an organization that introduced new technology and systems in order to effectuate...
find an example of an organization that introduced new technology and systems in order to effectuate changes in business processes, enhancements, and productivity gains (answer as many questions as you can): (1) What set of business problems was the organization trying to address? (2) How did the organization go about assessing the information requirements of the new system? What level of involvement, if any, did the end users have in the development of the new system? (3) What solution did...
Discuss ethical, global, and security challenges involved with implementing an ERP system. In your experience either...
Discuss ethical, global, and security challenges involved with implementing an ERP system. In your experience either as a customer or within your own organization, describe what led to the need to implement an ERP system. Explain the challenges you have faced when a new ERP system was implemented or attempted to be implemented. In any of your experiences with E-Business and E-Commerce, how could an ERP system come into play to create a better shopping experience for the customer?
2. Describe some ways that you personally use information technologies differently than you did just a...
2. Describe some ways that you personally use information technologies differently than you did just a few years ago. 3. Some organizations purposefully select a CIO that has strong business management backgrounds, not just technical experience. Under what organizational circumstances do you think this might be an effective choice? 4. Describe a new business for which you think a "virtual organization"—which has no physical office or headquarters—could be an effective design. What are some ways that the organization could use...
Choose an organization (Buffalo wild wings) with publicly traded shares and find information on that company's...
Choose an organization (Buffalo wild wings) with publicly traded shares and find information on that company's business strategy. Write a response of at least 150 words for each of the following five questions (total of at least 750 words): .Has the organization clearly identified its business niche and how it is different from its competitors? Explain your answer. What specific objectives has the firm set in conjunction with the new strategy? .What key strengths and weaknesses of the organization influenced...
This case assignment draws from the Business Information Systems and the Systems Acquisition and Development modules...
This case assignment draws from the Business Information Systems and the Systems Acquisition and Development modules (Chapters 5 to 8). Its purpose is to provide you with experience in analyzing organizational information systems, making recommendations to improve these systems, and formulating a plan to execute on your recommendations. 1. Recommend one of your alternatives that is the best solution to the main issue and justify your recommendation. Your justification should be based on the key decision criteria and you must...
what is the issue in Emaar case study ? (10marks) Emaar Properties specializes in creating value-added,...
what is the issue in Emaar case study ? (10marks) Emaar Properties specializes in creating value-added, master-planned communities that meet the full spectrum of lifestyle needs. Highlights include Downtown Dubai, the 500-acre mega-project including Burj Khalifa – the world’s tallest building, and The Dubai Mall—the world’s largest shopping and entertainment destination. Emaar is extending its expertise in developing master-planned communities internationally, and has established operations in the United Arab Emirates, Saudi Arabia, Syria, Jordan, Lebanon, Egypt, Morocco, India, Pakistan, Turkey,...
HASBRO DEVELOPS A GLOBAL SYSTEMS STRATEGY If you’ve ever played in a sandbox with a Tonka...
HASBRO DEVELOPS A GLOBAL SYSTEMS STRATEGY If you’ve ever played in a sandbox with a Tonka dump truck, accessorized a My Little Pony, manipulated a Transformer, or engaged in mock combat with a G.I. Joe, you have experienced a piece of the Hasbro Inc. juggernaut. Begun by brothers Henry, Hilal, and Herman Hassenfeld in 1923 as a pencil box and school supplies company, Hasbro transitioned to toys in the 1940s. Acquisitions, including Milton Bradley, Tonka, and Wizards of the Coast...
You have recently been hired by a new Japanese accounting firm, headquarter in Tokyo, as the...
You have recently been hired by a new Japanese accounting firm, headquarter in Tokyo, as the director of Information Systems and Telecommunications. Your assignment is to assist security posture of the firm and develop a security structure for this new company. Write your recommendations and reasons to the firm’s CEO. The firm has 600 employees in Tokyo, 50 in Houston, and is planning to open two branch offices in India and California. Ten accountants will be hired at each site....
QUESTION 1 Advanced Security Inc. was hired by the Treasury Bank Inc. for securing their systems....
QUESTION 1 Advanced Security Inc. was hired by the Treasury Bank Inc. for securing their systems. The first thing they did was implement the best practice if separation of domains. As a result of this The bank had to get a new domain name. any change made in the records points to only one party who could have made that change. If you are a technical person, you must have office in a particular area of the building. accessing outside...
ADVERTISEMENT
Need Online Homework Help?

Get Answers For Free
Most questions answered within 1 hours.

Ask a Question
ADVERTISEMENT