Case Study: Critical Controls that Could Have Prevented Target Breach

Case Study: Critical Controls that Could Have Prevented Target Breach

The SIG Resource Center is moving to The SIG Community. If you are a SIG Member, or enrolled in SIG University, and don’t have access yet, you can do so here. Already have access? Log in and visit the new SIG Resource Center.

Original Source: Sans Institute by Teri Radichel at https://www.sans.org/reading-room/whitepapers/casestudies/case-study-critical-controls-prevented-target-breach-35412

 

In December 2013 over 40 million credit cards were stolen from nearly 2000 Target stores by accessing data on point of sale (POS) systems. This paper will explore known issues in the Target breach and consider some of the Critical Controls that could have been used to both prevent this breach and mitigate losses. From what is known about the Target breach, there were multiple factors that led to data loss: vendors were subject to phishing attacks, network segregation was lacking, point of sale systems were vulnerable to memory scraping malware and detection strategies employed by Target failed. A possible solution for preventing and mitigating similar breaches using a defense in depth model will be presented using a multi-layered security strategy. Considerations of human factors that contributed to the losses in this case will also be addressed. 

Contributors:
Categories: , ,
SRC Type: , ,

Please log in to download the document.

Please log in to view the video.