Insider Threats
From Computing and Software Wiki
(Difference between revisions)
(→Employees) |
(→Former Employees) |
||
Line 12: | Line 12: | ||
===Former Employees=== | ===Former Employees=== | ||
- | + | Former employees who pose a threat to their former organization are typically disgruntled employees. They believe that the organization has “done them wrong” and feel that revenge is justified. They are able to gain access to sensitive material either: | |
- | + | *Directly: Through a back door. If an employee fears termination, he or she may prepare a backdoor access or alternative usernames and passwords in order to gain entry. They may also begin collecting proprietary data for later use. | |
+ | *Indirectly: Through former associates. A former associate may create a back door access for the former employee or may provide him or her with proprietary information. | ||
==Preventing Insider Threats== | ==Preventing Insider Threats== |
Revision as of 17:18, 23 March 2008
Definition
Contents |
Overview of Insider Threats
Etc
Sources of Insider Threats
Employees
Employees of an organization are amongst the greatest risk in terms of access to and potential harm with an organization’s sensitive material. Organizations typically assume that they can trust their employees. They believe that their employees are primarily interested in the productivity and successfulness of the organization. Therefore they are not considered to be of any possible danger and are considered last when a leak of sensitive material has occurred.
Contractors
Info
Former Employees
Former employees who pose a threat to their former organization are typically disgruntled employees. They believe that the organization has “done them wrong” and feel that revenge is justified. They are able to gain access to sensitive material either:
- Directly: Through a back door. If an employee fears termination, he or she may prepare a backdoor access or alternative usernames and passwords in order to gain entry. They may also begin collecting proprietary data for later use.
- Indirectly: Through former associates. A former associate may create a back door access for the former employee or may provide him or her with proprietary information.
Preventing Insider Threats
- Background checks
- Monitoring employee behaviour
- Restrict accounts
- Restrict the scope of remote access
- Enforce the principle of least privlege