Archives
- ► 2012 (8)
- ► 2011 (157)
- ► 2010 (174)
- ► 2009 (12)
Which topics would you like us to cover more?
Latest comments
- How to reset you Kindle
3, eve...
Thanks for this article and the related "Inside th...
By H K - How to reset you Kindle
3, eve...
How do you drain power on the board? I dont have r...
By Grace - How to reset you Kindle
3, eve...
You're welcome!
By Bas - How to reset you Kindle
3, eve...
Thanks man....removing the battery worked like a c...
By DaveMan - nHapi
example
Hi Slypete, Thank you for your comment. This way w...
By Bas - nHapi
example
Hello, Employing .Net dynamics, one can implement ...
By slypete - Implementing MLLP in C#
Hi Mayura, I'm not sure I understand your question...
By Bas - Implementing MLLP in C#
I have used SSL stream to secure the MLLP transact...
By Mayura
Latest tweets
| Dealing with the insider threat |
| Written by Division by Zero |
| Thursday, 02 December 2010 10:25 |
|
The hardest security threat to deal with is the insider threat. Most (by far!) security breaches come from insiders. As E. Cole points out detection and the reaction to this detection will improve your security a great deal, but (besides detection) how can you deal with this insider threat? Well... there are certain things you can do. First divide responsibilities between different employees. Make sure that every (critical) business process there are multiple employees involved. This way detection of a security breach is easier and the impact of such a breach will be smaller. The next thing would be to implement the principle of least privilege. Only allow employees to see what they need to see. This way a security breach will be less likely and the impact will be contained. The other benefit of this principle is traceability: you know who did what and where. The last thing you can do is getting your physical access policy right and train your employees on security matters. Make sure you know who is inside of your building and make sure that if someone is inside of your building this person doesn't have full access. And train you employees on the matter of security. Make sure they know all the policies. This won't guarantee full protection against insiders, but this will help you in detecting and containing security problems. Tags:
|
I'm feeling so happy today. I think I'll call in sick. - Loesje




