IT Security Case Study

1214 Words3 Pages

1. People failure points : Although people do not seem to be the primary failure point, the top management could have addressed IT security as a business issue and raised security awareness among its employees. This would have made the TJX employees more vigilant in their day to day tasks and aware of the security threats to the organization. Both the internal and external auditors failed to notice the key problems with TJX systems like absence of logs, absence of network monitoring, presence of unencrypted data and retention of customer data years after it should have been purged. TJX also passed the annual on-site audits and quarterly network scans in spite of being non compliant with Payment Card Industry Data Security Standards(PCI DSS). Both the internal auditing department and …show more content…

If non conformities are found in audits, immediate remedial actions must be taken to ensure compliancy. c) Conducting security assessments of the IT setup in a timely manner to ensure that necessary security controls are in place and to act upon any recommendations for improvement. Vulnerability assessment and penetration testing are great ways to check how well the security controls are performing their functions. d) Uploading software patches and updates according to the vendors recommendations to fix any security vulnerabilities. Recommended updates can also improve the usability and performance of the software. e) Conducting security awareness trainings among the employees on a periodic basis so that they are aware of the security policy of the organization and better prepared against various threats that could target them. TJX should focus on developing a strong security culture in the organization. Banners, posters, e-mail remainders are all great ways to promote secure practices among employees like using strong passwords, proper handling of private customer data

Open Document