Tag Archives: staff screening

ISNow – Insider Threat

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2009 issue (Volume 4, Issue 1), which was on the topic of Insider Threats:

“The insider threat is not new. But when companies seek to make cost savings by divesting themselves of their biggest assets, especially during a recession when uncertainty amongst the workforce is likely to be heightened and financial pressures felt more acutely, the likelihood and impact of the threat may increase. Normal controls, such as separation of duty, audit and training, may well get left behind as the remaining employees each try to do more, due to necessity and self-preservation. Whereas a company making significant changes should review their risk assessments, which may show increased controls are required.

Taking away data
Research appears to bear out the view that staff will take information when they leave a business, and may also exploit that information in any future role. Indeed, senior management and IT staff seem more likely to take information in their possession, which may be more valuable and accessible due to their roles.

Logic bombs
Recent scandals in Formula 1 have demonstrated the value of competitor intelligence, however obtained, and secret arrangements being exposed. Also, in the last few years there have been a number of cases of logic bombs, left just in case the person lost their job, and passwords being changed on departure.

Robust contracts
When dealing with an insider threat, the whole gamut of people, process and technology controls should be considered, preferably in that order, to help mitigate the risk; including robust contracts, staff screening, training, awareness, information marking, handling, access based on business need, role and least privilege, separation of duties, logging/audit, data loss prevention and so on.”

A PDF version of the magazine is available online at:

http://www.bcs.org//upload/pdf/isnow-autumn09.pdf