Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • Pentagon Seeks a New Generation of Hackers
  • EA's Spore Spawns on BitTorrent
  • Being Acquitted Versus Being Searched (YANAL)
  • Registered Traveler Company Frozen After Losing Flier Data
  • ACLU Urges Senate Committee to Pass Strong State Secrets Bill
  • Met given real time c-charge data - BBC NEWS
  • Grokster Case Lumbers On; Judge To Issue Permanent Injunction

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

Employee profiling: A proactive defense against insider threats

Submitted by MacRonin on May 4, 2007 - 2:37am.
  • Companies
  • Hmmm
  • Privacy
  • Security
  • Standards

Employee profiling: A proactive defense against insider threats: "They might seem like normal employees, working away quietly like everybody else. But they're not. They're criminal insiders, using their privileged positions inside companies everywhere to access and steal confidential data or cause mayhem on the company's IT systems.

How can organizations protect themselves against these miscreants? How can enterprises weed out, let alone find, malicious insiders in their midst?

One way might be to build a profile of corporate turncoats. Once singled out, they can be scrutinized more closely than other employees. However, before starting an employee profiling program, there are three key questions to ask: What is the profile of a criminal insider? Is it legal or appropriate to single out suspected thieves? Is there a clever technical solution -- such as identity and access management -- to stop corporate sabotage without the fuss and hazards of profiling?

Building the employee profiling model
A profile of criminal insiders does exist. Carnegie Mellon's Computer Emergency Readiness Team (CERT) issued its first Insider Threat Study in 2002 (.pdf). Since then, CERT has updated the work annually in conjunction with the U.S. Secret Service. Their work has become the foundation for profiling potential computer criminals inside companies and organizations.

The CERT study focuses on three types of insider crimes: fraud, information theft and sabotage. The study says the profile of the typical insider crook is different for each crime. Those committing fraud tend to be current employees, evenly divided between males and females and mostly not in technical or management positions. Those who stole information, on the other hand, were overwhelmingly male employees in technical positions."

(Read Original Article.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
  • China thinks twice – and its 300m internet users scent a rare victory
  • Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
  • Supreme Court Serves Up Remote-Recording Victory
  • Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
  • ATM Vendor Halts Researcher’s Talk on Vulnerability
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.