It 205 Tjx

Submitted by: Submitted by

Views: 342

Words: 913

Pages: 4

Category: Science and Technology

Date Submitted: 05/14/2012 03:05 PM

Report This Essay

1. List and describe the security controls in place. Where are the weaknesses?

TJX Companies had inadequate and under-maintained security systems in place. One example of this was at a St. Paul MN store in which TJX was utilizing a wireless network without the proper encryption (WEP vs. WPA) to ensure hackers were not able to access the system. While using such outdated coding, the store also did not set in place the proper firewalls on the network. And to compound matters even more, the security software that actually had been purchased hadn’t been properly installed. Simply correcting these oversights could have help in avoiding such a significant data theft scenario. Such oversights allowed hackers to break into the network, create their own user accounts and essentially spy on the transactions that were made. When credit card or bank card transactions were made, the hackers were able to glean personal and bank information because the transactions were process and transmitted to the banks without the proper encryption. After having stolen the information, this data was then criminally sold - over 200,000 credit card numbers used, resulting in fraud losses of over $75 million. These losses do not account for the numerous fines incurred by the merchants, the business losses of said merchants, and even the costs incurred by the consumers themselves. However, the banks have suffered the majority of the losses - an estimated $300 million.

2. What tools and technologies could have been used to fix the weaknesses?

The tools and technologies that could have been used to fix the weaknesses were to upgrade their computers to the latest security system. The computers could have had firewalls installed, in order for hackers to stay away. An anti-virus could have been installed in order for malicious data to have access to the computers. The computers firewall should had been installed correctly as well. The first change that would need to be made it to make a...