Emerging threats
Running head: CAPITAL ONE DATA VIOLATION 1
CAPITAL ONE DATA VIOLATION 3
This breach was a technical problem as the company experienced a data breach which is said to have been caused by a misconfigured web application firewall on the Apache that is hosted on AWS. This misconfigured WAF gave the attackers a chance to trick the firewall which in turn submitted some requests to the back end user which in the event gave out the customer data (Amir et al. 2018).
With the aid of the different silver lining, the investigation used different monitoring tools which made it possible for the organization to identify the problem. This activities were traced to a certain employee account on GitHub. It’s evident that the firewall configuration was not able to prevent this breach although some of the other controls made it possible to tracking the individual responsible. On the positive side, layered security maintains security in the different governance, identifying, preventing, detecting and enables recovery methods (Wang et al. 2019).
Thompson managed to breach the company as the company had configured their Amazon server. However there are some possibilities that Thompson used an inside traitor in accessing the firewall. This give more reason why governance is an important aspect in the organization setup (Amir et al. 2018).
This has made the company to improve on their governance regarding the fact that this is most critical as it’s very difficult to achieve a security program more secure and lack a proper management support. After the technical experts have implemented the necessary technical controls, the management should be able to manage the framework to enable the operation of the organization. There is no greater benefit to the organization as at all layered security would hinder operation of the business (Wang et al. 2019).
Amir, I., Gruner, E., & Zilber, B. (2018). U.S. Patent No. 10,157,280. Washington, DC: U.S. Patent and Trademark Office.
Wang, T., Wang, Y. Y., & Yen, J. C. (2019). It's Not My Fault: The Transfer of Information Security Breach Information. Journal of Database Management (JDM), 30(3), 18-37.