{"id":14160,"date":"2024-08-20T00:21:04","date_gmt":"2024-08-19T18:21:04","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14160"},"modified":"2024-08-20T00:21:04","modified_gmt":"2024-08-19T18:21:04","slug":"what-is-your-definition-of-insider-threat","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/what-is-your-definition-of-insider-threat\/","title":{"rendered":"What is Your Definition of Insider Threat?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/images.contentstack.io\/v3\/assets\/blt36c2e63521272fdc\/blt7a294fb0c4991bc7\/6650c85ff5cbb759828a2a63\/SSA_-_Blog_-_What_is_Your_Definition_of_Insider_Threat_340_x_340.jpg\" alt=\"SSA - Blog - What is Your Definition of Insider Threat__340 x 340.jpg\" width=\"340\" height=\"340\" \/><\/p>\n<p>When discussing human security, &#8220;Insider Threat&#8221; is a term that comes up frequently. Many organizations have insider threat programs, but the definition of an insider threat varies significantly from one organization to another. How you define this term is crucial because it directly influences how you approach and implement solutions. While I won\u2019t define insider threat for your organization, I hope to outline different categories that can shape your understanding and explain how these categories impact the solutions you put in place.<\/p>\n<h3><\/h3>\n<h3><\/h3>\n<h3>What is an Insider Threat?<\/h3>\n<p>In my experience, insider threats typically fall into four categories. The common thread among them is that they all involve a trusted individual\u2014be it an employee, contractor, intern, or volunteer. Whether you include third-party vendors in this definition is up to you, though they are often managed separately under Third-Party Risk Management (TPRM). The four categories are:<\/p>\n<p><strong>1. Malicious Insider<\/strong><br \/>\nA malicious insider is a trusted individual who intentionally causes harm. Their motivations can vary\u2014financial gain, revenge, ego, and more. These individuals exploit their trusted access to inflict damage. A typical example is an employee who leaves the company and takes sensitive information, like customer data or trade secrets, with them. Although such incidents are rare, they have a high impact when they do occur. Interestingly, regardless of how organizations define insider threats, this category is often the primary focus of insider threat programs.<\/p>\n<p><strong>2. Negligence<\/strong><br \/>\nIn cases of negligence, harm is not caused intentionally but results from failing to follow security policies and procedures. For example, someone might ignore or bypass security rules to complete their work, such as taking sensitive files home on a personal laptop or forwarding them to a personal email account. While they know they are violating policy, they may feel it&#8217;s necessary to do their job. This can indicate that security policies are too complex, confusing, or obstructive to daily tasks.<\/p>\n<p><strong>3. Mistakes<\/strong><br \/>\nHuman error is a significant driver of security breaches. Mistakes happen when people, in the course of their work, inadvertently cause incidents due to carelessness, lack of awareness, or inadequate training. A common example is what Verizon\u2019s Data Breach Investigations Report (DBIR) calls \u201cmisdirection,\u201d where an email is accidentally sent to the wrong person due to auto-complete features. For instance, you might intend to email Sarah from finance, but end up sending sensitive documents to your daughter\u2019s basketball coach, who is also named Sarah. Though it might seem trivial, human errors like this account for 25% of breaches globally. This often suggests that technology or policies are too complicated, making such mistakes easier to make.<\/p>\n<p><strong>4. Victim<\/strong><br \/>\nIn this category, the individual becomes a victim of an attack, such as falling for a phishing email or a vishing phone scam.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/images.contentstack.io\/v3\/assets\/blt36c2e63521272fdc\/bltae889d4cec4e0720\/6650cba9466a1c7157dec433\/insider_threat_gaphic.png\" alt=\"definition of insider threat graphic\" \/><\/p>\n<h3>Define the Solution<\/h3>\n<p>The next step is to determine which of these categories fit your definition of an insider threat. This decision is yours to make. However\u2014and this is a crucial point\u2014different categories require different management approaches.<\/p>\n<p>For <strong>malicious insiders<\/strong>, you manage the risk similarly to a counter-intelligence program. Start with thorough background checks to hire individuals likely to be trustworthy. Then, implement processes and controls to minimize the damage a trusted individual can inflict. Finally, actively search for signs of malicious behavior\u2014this is challenging because these individuals are trusted, and their motivations or actions often differ from past incidents, making common indicators hard to identify.<\/p>\n<p>For the other three categories\u2014<strong>negligence, mistakes, and victimization<\/strong>\u2014your approach should be the opposite. These individuals are good, trustworthy people who want to do the right thing. Your job is to empower them by simplifying security. This is where Security Awareness and Training programs play a vital role. By equipping people with the knowledge, skills, and tools they need, you enable them to use your organization\u2019s technology safely and securely.<\/p>\n<p>The strategy for handling malicious insiders should not only differ but might also need to be led by a separate team, as it requires a unique mindset and skill set. You are essentially hunting for harmful behavior. In contrast, when dealing with negligence, mistakes, and victimization, you are supporting and guiding good behavior.<\/p>\n<p>Ultimately, how you define insider threat is up to you. My only request is that if you use the term &#8220;insider threat&#8221; or have an insider threat program, clearly define what it means for your organization and adjust your security measures accordingly.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Ch\u00fang t\u00f4i h\u1ed7 tr\u1ee3 nh\u01b0 th\u1ebf n\u00e0o<\/strong><\/p>\n<p>If you need to know more about Insider Threat, you\u2019re in the right place, we\u2019re here to help! DTA is SANS Institute\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Nh\u1ea5n v\u00e0o \u0111\u00e2y \u0111\u1ec3 t\u00ecm hi\u1ec3u th\u00eam:\u00a0<a href=\"https:\/\/dtasiagroup.com\/vi\/sans\/\">https:\/\/dtasiagroup.com\/sans\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>How you define insider threat is critical, because how the problem is defined will drive how you define and implement the solution.<\/p>","protected":false},"author":11,"featured_media":14161,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14160"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14160\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/14161"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}