Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Online Bank Offers Software to Secure Transactions but What About Support? | Main | Mobile Device Security »

Employee Canned for Exposing Blank Passwords at TJX

The Register is reporting a TJX employee was fired for Internet postings about blank passwords on company servers as recently as a few weeks ago. After the long drawn out saga of their data breach last year this is the last place you'd expect to hear these accusations. Let's assume the accusations are true, should the employee have been fired?

Yes, he didn't do enough to get the problem fixed:

He said he brought the security issues to the attention of a district loss prevention manager name Allen in late 2006, and repeatedly discussed them with store managers. Except for a stretch when IT managers temporarily tightened password policies, the problems went unfixed.

and

"Not one single thing was done. My store manager even posted the password and username on a post-it note. I told her not to do that."

One letter to the CEO, the auditors or the consultants brought in to help with security could bypass mid-level management stonewalling. Going public is a whistle blowers last resort, this case doesn't seem to have reached that point yet.

One has to wonder who in the management chain was fired along with the employee. If these reports are true and they are not isolated to a single store then there is a profound organizational problem that needs to be addressed quickly. Firing one employee and maybe a local manager or two isn't going to do it.

In the mean time I'll continue to shop elsewhere.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/742

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net