Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Into the DTV era, with no broadcast flag mandate
  • Microsoft gathers hackers in Redmond
  • ACLU Presents Arguments Today For Congressional Select Committee To Reform U.S. Surveillance Policies
  • The Pirate Bay Hit By Another Legal Volley
  • Anti-Piracy Group Violates Swiss Law to Track File Sharing
  • Psychology and Security Resource Page
  • What is your affiliation with OptOut.com ?

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Employee profiling: A proactive defense against insider threats

Submitted by MacRonin on May 4, 2007 - 2:37am
  • Carnegie Mellon
  • Companies
  • Hmmm
  • Privacy
  • Security
  • Standards

Employee profiling: A proactive defense against insider threats: "They might seem like normal employees, working away quietly like everybody else. But they're not. They're criminal insiders, using their privileged positions inside companies everywhere to access and steal confidential data or cause mayhem on the company's IT systems.

How can organizations protect themselves against these miscreants? How can enterprises weed out, let alone find, malicious insiders in their midst?

One way might be to build a profile of corporate turncoats. Once singled out, they can be scrutinized more closely than other employees. However, before starting an employee profiling program, there are three key questions to ask: What is the profile of a criminal insider? Is it legal or appropriate to single out suspected thieves? Is there a clever technical solution -- such as identity and access management -- to stop corporate sabotage without the fuss and hazards of profiling?

Building the employee profiling model
A profile of criminal insiders does exist. Carnegie Mellon's Computer Emergency Readiness Team (CERT) issued its first Insider Threat Study in 2002 (.pdf). Since then, CERT has updated the work annually in conjunction with the U.S. Secret Service. Their work has become the foundation for profiling potential computer criminals inside companies and organizations.

The CERT study focuses on three types of insider crimes: fraud, information theft and sabotage. The study says the profile of the typical insider crook is different for each crime. Those committing fraud tend to be current employees, evenly divided between males and females and mostly not in technical or management positions. Those who stole information, on the other hand, were overwhelmingly male employees in technical positions."

(Read Original Article.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.