Preventing insider attacks

by John Evelyn on February 7, 2007

Carnegie Mellon CyLab has just published the second edition of its Common Sense Guide to Prevention and Detection of Insider Threats.  (Hat tip to The Register.)

Insider threats such as fraud or sabotage are, in many ways, the most insidious and most dangerous.  This report analyses 150 actual cases.  It recommends that companies:

  1. Institute periodic enterprise-wide risk assessments.
  2. Institute periodic security awareness training for all employees.
  3. Enforce separation of duties and least privilege (i.e. people only get the computer access and rights they need to do their job and not more).
  4. Implement strict password and account management policies.
  5. Log, monitor and audit employee online activities.
  6. Use extra caution with system administrator and privileged users.
  7. Actively defend against malicious code.
  8. Use layered defence against remote attacks.
  9. Monitor and respond to suspicious or disruptive behaviour (often the precursor to more serious problems).
  10. Deactivate computer access when someone leaves the company.
  11. Collect and safe data for use in investigations.
  12. Implement secure backup and recovery processes.
  13. Clearly document insider threat controls.

Technorati Tags: , , , ,

{ 2 comments… read them below or add one }

Terry Verney February 7, 2007 at 9:51 am

I have reccieved in my email, a very authentic looking request to supply my personal informatio to an outside paty pretending to be Lloyds tsb. I am a little smarter than the average bear (a bit of a giveaway in the subject bar, stating ‘Expiration Of Your Lloyds TSB Online Banking Access’). As I don’t have an account with ltsb, I figured it must have been a phish. Don’t go any further than to put it in your wastebasket with this rubbish, Lloyds, or in fact, anyone, will NEVER ask you for information in this way. Good luck
Terry

kathryn March 11, 2007 at 2:00 pm

Thanks for the advice!

kathryn
http://www.scamemail.co.uk

Leave a Comment

Previous post:

Next post: