Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Definitions: Internal Threat

0

Created on: Jan 26, 2009 1:09 PM by CrystalBedell - Last Modified:  Jan 26, 2009 1:12 PM by CrystalBedell

Definition

Internal threat refers to the threat posed by the users of  an organization’s network and/or information systems. These users are insiders  in that they are authorized, at some level, to use the organization’s technological  resources. However, every user poses a threat to the integrity and availability  of those resources, either through malicious intent or accidental misuse.

 

Business applications

The internal threat is often considered an organization’s biggest security risk because users require a level of trust to carry out their  day-to-day tasks. Also, organizations tend to focus on securing the network perimeter from outsiders, as opposed to securing network resources from insiders.

 

Experts recommend educating users about security and proper computer use to help reduce internal threat. There are also technical controls organizations can implement. Together, security-awareness training and technical controls can help prevent malicious attacks and accidental misuse of IT resources.

 

 

Deployment concerns

There are several  dynamics to the internal threat. We’re not just talking about insiders sharing  passwords. There’s also the full-time telecommuter versus the office worker; the user working around stringent policies to get her work done versus the accountant shaving a few pennies off the numbers. Then, of course, there is the laid-off IT manager  who uses his access as blackmail. Organizations need to account for these many possibilities and implement appropriate risk-mitigation techniques.

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

The IT Service Catalog Management Toolkit

Bridge the IT-business gap once and for all! A well documented IT services catalog is the conduit for IT services to the rest of the company.

Learn more >

The Complete IT Policy Kit

Download a comprehensive bundle containing over 40 IT policy templates. Each can be modified to align with your specific business requirements. Complete instructions are included.

Learn more >

Cost Cutting through Server Consolidation

Products, management tools, and industry insights that enhance the value of virtualization for your business.

Data Warehousing for Business Intelligence

Comprehensive storage solutions for better data access and retrieval, leading to better-informed business decisions.

Database Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Greening IT with Server Consolidation

Learn how virtualization reduces the TCO of managing your date, while contributing towards your sustainability efforts.

IP Telephony: Reliability You Can Count On

This white paper will examine the effects of three different architecture platforms on the ability to deliver IP-based telephony systems that are both highly available and cost effective.

Lower Total Cost of Ownership for Mission-Critical Applications

This white paper discusses a middleware platform that enables companies to lower their total cost of ownership, adopt more standards-oriented platforms, and leverage existing IT assets while not compromising on the mission critical nature of their business applications.