Information Security

Activate your FREE membership today  |  Log-in

  • Visit other TechTarget ANZ sites: 
Posted
Aug 6, 2006
 |  By:  Ed Skoudis

Creating a security awareness program

Bookmark and Share

I am working on a security awareness and internal security program. Where can I find statistical information on insider threats, lost laptops, etc?

There are periodic surveys about these problems. The following three surveys are good sources to start with:

  • Insider Threat Statistics:
    http://www.schneier.com/blog/archives/2005/12/insider_threat.html
  • 'Insider Threat' Study Reveals That Trusted Employees Are Exposing Co-Workers' Personal Information:
    http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&STORY=/www/story/08-22-2005/0004091867&EDATE
  • Beware of insider threats to your security:
    http://www.viack.com/_download/200408_cdm.pdf

Each survey describes the persistent and pernicious insider problem of many employees inadvertently or purposely putting their organizations at risk. However, these surveys can be inconsistent, especially the ones that compare the number of external attacks to internal attacks (from employees, etc.). Some surveys show a huge number of external attacks, while others show a preponderance of the latter.

When discussing this threat with management, emphasize the need to defend against both insiders and outsiders, and how to leverage some tools across both threats, while using other tools that focus predominantly on one or the other. If you put all of your defensive eggs in the outsider threat basket, your organization could be in serious peril. Thus, a blended approach is vital.


TechTarget ANZ sites: SearchCIO.com.au | SearchNetworking.com.au | SearchSecurity.com.au | SearchStorage.com.au | SearchVoIP.com.au

WF Online community sites: ElectricalSolutions | ElectronicsOnline | FoodProcessing | InMotionOnline | LabOnline | ProcessOnline | RadioComms | SafetySolutions | SustainabilityMatters | Voice&Data

Copyright © 2010 Westwick-Farrow Pty Ltd. All rights reserved.
About Us | Contact Us | TechTarget