Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Networking Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Study notes link between IT sabotage, work behavior

Workers likely to sabotage corporate systems can be identified ahead of time

February 7, 2007 12:00 PM ET

TechWorld.com - Workers who sabotage corporate systems are almost always IT workers who exhibit specific negative office behavior, according to recent research.

That is the conclusion of the U.S. military in conjunction with Carnegie Mellon University’s CERT Coordination Center, which together analyzed insider cybercrimes across a variety of critical industry sectors.

The research suggests that potential troublemakers should be easy to spot. Nearly all the cases of cybercrime investigated were carried out by people who were disgruntled and paranoid, generally showed up late, argued with colleagues and generally performed poorly.

According to the study, 86% of those who committed cybercrimes held technical positions and 90% had systems administrator or privileged system access. Almost half -- 41% -- of those who sabotaged IT systems were employed at the time they did it, but most crimes were committed by insiders following termination. Most incursions -- 64% -- involved VPNs and old passwords that had never been terminated, highlighting a lack of security controls and gaps in their organizations’ access controls.

As a result, Carnegie Mellon has developed a methodology that it said can help detect insider threats as early as possible, involving management, IT, human resources, security officers and others who "must understand the psychological, organizational and technical aspects of the problem, as well as how they coordinate their actions over time."

The university's study is titled Management and Education of Risks of Insider Threat (MERIT): System Dynamics Modeling of Computer System Sabotage.

According to security management vendor Calum Macleod of Cyber-Ark Software Ltd., most organizations are leaving themselves exposed by "not paying due care and attention to the people who are charged with looking after their systems and applications." Even outsourcing cannot fully resolve the problem, he said.

Macleod's solution is password management. This means ensuring that policies and standards are in place to control administrative access by containing the number of privileged accounts to three or fewer. This reduces the difficulty of managing those accounts. Passwords also need to be changed regularly.

Macleod concluded: "So as far as doing the right thing, I’d suggest that you start from the basis that your IT [staffers] are the biggest risk to your organization's security, and if [any] of them disputes this, remember that arguing with colleagues was one of the clear signs of an impending attack.

"And automate the whole process," Macleod said. "If privileged password management is not on your shopping list in 2007, it may already be too late."


Reprinted with permission from

For more enterprise technology news from the U.K., please visit TechWorld.com. Copyright 2006 IDG, all rights reserved.

Jump to comments

cert

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Enterprise 2.0 Applications - Block or Not?
Learn what your organization should do to control Enterprise 2.0 Applications.  

Product Overview Brochure
Learn how to deliver secure data and applications wherever and whenever they're needed.  

How to Secure and Accelerate Your Oracle Applications
Learn about the escalating application performance and security challenges facing corporations, today!  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.  

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Accelerate SSL Encrypted Applications
Gain complete visibility into SSL application sessions, making it easy to apply appropriate acceleration and security controls to all SSL traffic.  

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs