Daily using/supporting

Get Firefox browser!
Get Thunderbird!
Get Opera browser!
Get The Gimp!
Get Inkscape!
Get LibreOffice!
Get Videolan!
Get Linux!
Get Mandriva!
Get Joomla!
Hacker Emblem

Archives

Which topics would you like us to cover more?

Latest comments

Latest tweets

about 1 day ago Using REDIPS.drag to add drag and drop to your .Net webapplication #li #dib0 http://t.co/n8zY3s7d
about 7 days ago http://t.co/cknQcDbo #Kindle
about 15 days ago Freedom isn't the ability to choose what to do or say, but the ability to choose what not to do or say #freedom
about 29 days ago http://t.co/61KTQknI #Kindle
12 Apr 2012 Force the use of a networking adapter using C# #li #dib0 http://t.co/ZTJOPzOz
9 Apr 2012 Mandriva 2010.2 and USB devices in Virtualbox http://t.co/fwq9gbHB
9 Apr 2012 Execute a http request to you own site with PHP http://t.co/DIvWPrpd
Home Architecture, security and coding Dealing with the insider threat
Dealing with the insider threat
Written by Division by Zero   
Thursday, 02 December 2010 10:25

The hardest security threat to deal with is the insider threat. Most (by far!) security breaches come from insiders. As E. Cole points out detection and the reaction to this detection will improve your security a great deal, but (besides detection) how can you deal with this insider threat?

Well... there are certain things you can do. First divide responsibilities between different employees. Make sure that every (critical) business process there are multiple employees involved. This way detection of a security breach is easier and the impact of such a breach will be smaller.

The next thing would be to implement the principle of least privilege. Only allow employees to see what they need to see. This way a security breach will be less likely and the impact will be contained. The other benefit of this principle is traceability: you know who did what and where.

The last thing you can do is getting your physical access policy right and train your employees on security matters. Make sure you know who is inside of your building and make sure that if someone is inside of your building this person doesn't have full access. And train you employees on the matter of security. Make sure they know all the policies.

This won't guarantee full protection against insiders, but this will help you in detecting and containing security problems.

 

Add comment


Security code
Refresh

I'm feeling so happy today. I think I'll call in sick. - Loesje


© 2009 - 2012, Division by Zero

Template based on the empire template by joomlashack 

Valid XHTML 1.0 Strict  Valid CSS!  Creative Commons License
This work by Division by Zero is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Netherlands License.