- Trusted HR employees of Home Depot have allegedly stolen PII data from the company for nefarious purposes.
- A draft project charter has been created and team members identified to been incident recovery efforts.
Objective
- Damage assessment and investigation of the impact of the internal attack on Home Depot.
- To assess the efficiency and effectiveness of current status of the security program.
- To determine the operational effectiveness of the security program after the recent internal data breach.
Investigation and Analysis
- Security policies and programs are reviewed
California’s Unfair Competition Law
California’s Consumers Legal Remedies Act
Breach of Contract
Negligence
- Computer evidence is collected, documented, maintained for future legal proceedings
- Damage assessment will determine how the incident occurred and what happened
- Analysis of current threats and controls
References
Benefits
- Whitman, M. E., & Mattord, H. J. (2012). Principles of information security (Fourth ed.). Boston, MA: Cengage Learning.
- Stockman, R. (2014, February 5). Home Depot employees charged with stealing co-workers' personal info. Retrieved from wsbtv.com: http://www.wsbtv.com/news/news/local/home-depot-employees-charged-stealing-co-workers-p/ndDSc/
It is necessary to reassess the current state of security, update the security plan as needed, and analyze the incident in order to determine what improvements can be made.
Security controls should be periodically tested internally for effectiveness and consistency.
Home Depot
Data Breach
Vulnerabilities
- Address safeguards that failed to stop or limit the breach.
- Ensure appropriate access controls are in place.
- Evaluate monitoring capabilities for improvement in detection and reporting methods.