The CERT guide to insider threats how to prevent, detect, and respond to information technology crimes (theft, sabotage, fraud)

For each, they present a crime profile describing how the crime tends to evolve over time, as well as motivations, attack methods, organizational issues, and precursor warnings that could have helped the organization prevent the incident or detect it earlier. Beyond identifying crucial patterns of s...

Full description

Bibliographic Details
Main Author: Cappelli, Dawn
Other Authors: Moore, Andrew, Trzeciak, Randall
Format: eBook
Language:English
Published: Upper Saddle River, NJ Addison-Wesley 2012
Series:The SEI series in software engineering
Subjects:
Online Access:
Collection: O'Reilly - Collection details see MPG.ReNa
LEADER 04700nmm a2200601 u 4500
001 EB001948400
003 EBX01000000000000001111302
005 00000000000000.0
007 cr|||||||||||||||||||||
008 210123 ||| eng
020 |a 0132906058 
020 |a 9780132906050 
050 4 |a HV6773 
100 1 |a Cappelli, Dawn 
245 0 0 |a The CERT guide to insider threats  |b how to prevent, detect, and respond to information technology crimes (theft, sabotage, fraud)  |c Dawn Cappelli, Andrew Moore, Randall Trzeciak 
246 3 1 |a How to prevent, detect, and respond to information technology crimes (theft, sabotage, fraud) 
260 |a Upper Saddle River, NJ  |b Addison-Wesley  |c 2012 
300 |a xxxv, 389 pages  |b illustrations 
505 0 |a Includes bibliographical references and index 
653 |a Computer security 
653 |a Social Sciences / hilcc 
653 |a Sécurité informatique 
653 |a Computer networks / Security measures / http://id.loc.gov/authorities/subjects/sh94001277 
653 |a Information technology / Security measures / fast 
653 |a Employee crimes / Prevention / fast 
653 |a Data protection / fast 
653 |a Employee crimes / Prevention 
653 |a Computer networks / Security measures / fast 
653 |a Criminology, Penology & Juvenile Delinquency / hilcc 
653 |a Technologie de l'information / Sécurité / Mesures 
653 |a Information technology / Security measures 
653 |a Data protection / http://id.loc.gov/authorities/subjects/sh85035859 
653 |a Réseaux d'ordinateurs / Sécurité / Mesures 
653 |a Computer crimes / Prevention 
653 |a Social Welfare & Social Work / hilcc 
653 |a Computer security / fast 
653 |a Computer crimes / Prevention / fast 
653 |a Protection de l'information (Informatique) 
700 1 |a Moore, Andrew 
700 1 |a Trzeciak, Randall 
041 0 7 |a eng  |2 ISO 639-2 
989 |b OREILLY  |a O'Reilly 
490 0 |a The SEI series in software engineering 
776 |z 0321812573 
776 |z 9780321812575 
856 4 0 |u https://learning.oreilly.com/library/view/~/9780132906050/?ar  |x Verlag  |3 Volltext 
082 0 |a 331 
082 0 |a 658.4/78 
082 0 |a 500 
082 0 |a 364.1 
520 |a For each, they present a crime profile describing how the crime tends to evolve over time, as well as motivations, attack methods, organizational issues, and precursor warnings that could have helped the organization prevent the incident or detect it earlier. Beyond identifying crucial patterns of suspicious behavior, the authors present concrete defensive measures for protecting both systems and data. This book also conveys the big picture of the insider threat problem over time: the complex interactions and unintended consequences of existing policies, practices, technology, insider mindsets, and organizational culture. Most important, it offers actionable recommendations for the entire organization, from executive management and board members to IT, data owners, HR, and legal departments.  
520 |a With this book, you will find out how to Identify hidden signs of insider IT sabotage, theft of sensitive information, and fraud Recognize insider threats throughout the software development life cycle Use advanced threat controls to resist attacks by both technical and nontechnical insiders Increase the effectiveness of existing technical security tools by enhancing rules, configurations, and associated business processes Prepare for unusual insider attacks, including attacks linked to organized crime or the Internet underground By implementing this book's security practices, you will be incorporating protection mechanisms designed to resist the vast majority of malicious insider attacks 
520 |a Since 2001, the CERT® Insider Threat Center at Carnegie Mellon University's Software Engineering Institute (SEI) has collected and analyzed information about more than seven hundred insider cyber crimes, ranging from national security espionage to theft of trade secrets. The CERT® Guide to Insider Threats describes CERT's findings in practical terms, offering specific guidance and countermeasures that can be immediately applied by executives, managers, security officers, and operational staff within any private, government, or military organization. The authors systematically address attacks by all types of malicious insiders, including current and former employees, contractors, business partners, outsourcers, and even cloud-computing vendors. They cover all major types of insider cyber crime: IT sabotage, intellectual property theft, and fraud.