Attacks/Breaches
3/6/2014
03:00 PM
Connect Directly
RSS
E-Mail

Target CIO's Resignation: 7 Questions

After the data breach, why didn't the buck stop with PCI assessors or CEO? Search for accountability reveals flawed system, much finger-pointing.

Former Target CIO Beth Jacob
Former Target CIO Beth Jacob

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Laurianne
50%
50%
Laurianne,
User Rank: Apprentice
3/10/2014 | 2:40:52 PM
Re: Where is the CEO's responsibility?
Who would you put in charge of security if not the CIO?
ThomasW784
50%
50%
ThomasW784,
User Rank: Apprentice
3/10/2014 | 2:07:13 PM
Re: Where is the CEO's responsibility?
Yes, JREY146's post is the article that Information Week should have written.

Target decided as a matter of business strategy to run the risk of customers' data loss rather than incur the cost of duely diligent security. 

OK, part of being in the C-suite (CIO in this case) means falling on your sword, or agreeing to be pushed on it. But this is classic scapegoating. Candidates to fill the CIO position will want to ask whether Target is going to give data security higher priority than before, and whether they'll spend the money to make it so.

It's also time for the rest of the e-commerce world (banks, credit card companies, regulators...) to admit that core data losses are a different kind of problem, not the same as the slow trickle of individual identity compromises, and stop treating all data losses as just the cost of being in this business.
marylori
50%
50%
marylori,
User Rank: Apprentice
3/10/2014 | 3:08:20 AM
Garcinia Cambogia Pro
 

Thank you for broadening my knowledge on this aspect to groom up my skills here.

 

Garcinia Cambogia Gold  / Garcinia Cambogia Pro
JFREY146
50%
50%
JFREY146,
User Rank: Apprentice
3/9/2014 | 4:10:48 PM
Where is the CEO's responsibility?
Isn't it the CEO's responsibility to run the company?  For years Cybersecurity has been on the forefront, when are CEOs and their C-suite pals going to wake up and realize that putting the CIO in charge of information security is like bringing an Accountant to a murder trial?  Information Security is not a tehcnical problem, it is a business problem and should have a strategy that aligns with the business along with representation at the C level.  Additionally, boards of directors are ultimately responsible for the business (with delegation to the CEO).  They should be demanding these organziational alignments, regular updates, etc.  Doing all this will not stop the breaches 100%, but it will make them much more secure than they are now...
NielH146
50%
50%
NielH146,
User Rank: Apprentice
3/7/2014 | 5:18:50 PM
Re: Retail IT security woes
If you think she resigned of her own choice, you are kidding yourself.  This was not about taking accountability, this is about Target firing her under the guise of her resignation. 

 
MyW0r1d
100%
0%
MyW0r1d,
User Rank: Apprentice
3/7/2014 | 10:30:46 AM
Re: Retail IT security woes
As long as they "are" smart CIOs.  She had a long history with Target, back to 1984 if I recall her bio correctly, a degree in retail sales and MBA which means she knew the retail industry from Target's point of view and it is important to provide a path for your best employees.  That does not always translate however to being able to manage and fully understand technology's risks/security.  30 years in the same company also promotes tunnel vision.  In smaller companies, you might be able to get away with running on autopilot (as one of my bosses once said, promoted beyond his level of competence) but as one of the largest, leading retailers they should have had a CIO with CIO credentials.  Hiring CISO and audit/compliance professionals is a step in right direction, after leaving the barn door open.
WKash
50%
50%
WKash,
User Rank: Apprentice
3/6/2014 | 5:07:04 PM
Assessors
You raise a good point about the PCI assessors. Not holding assessors accountable in some way is the moral equivalent of letting an auditing firm off the hook in the face of corporate fraud. Hopefully enterprises haven't forgotten the lesson of Enron and Arhur Andersen.  Now that government sector is embracing third party assessors with FedRAMP, the role of IT / security assessors is likely to become more important (and probably more competitive.)  In the meantime, it's hard to believe Target is only now looking to hire a CISO.  Just goes to show,  risk management still doesn't prepare you for Black Swan events.

 
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Moderator
3/6/2014 | 4:45:18 PM
Re: Retail IT security woes
Is may be worth asking why other CIOs have remained in their jobs after major breaches. After all, this is hardly the first massive data breach or organization that has been compromised.
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
3/6/2014 | 3:56:59 PM
Re: Retail IT security woes
Personally I find it refreshing to see a leader take ownership of what happened on her watch. Is it fair? Well, as we all know, life isn't fair. But the US could do with more accountability by top leaders.
Laurianne
50%
50%
Laurianne,
User Rank: Apprentice
3/6/2014 | 3:19:18 PM
Retail IT security woes
Don't go into retail? If the smart CIOs walk away from retail, we're in trouble. Turnaround experts have an opportunity here, right?
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2531
Published: 2014-10-21
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) R...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.