insider threat Flashcards
1
Q
The three components needed for insider fraud to take place are:
A
motivation, opportunity and rationalization
2
Q
Name 3 ways to mitigate insider threats
A
Prevent
Detect
Respond
3
Q
Name 3 Motivations
A
Any 3 from:
Espionage Sabotage Theft of Intellectual Property Financial gain Revenge Curiosity/Because they can Vanity
4
Q
Name 3 ways to Prevent insider threats
A
Any 3 from:
- Only give users as much privilege as they need to do their job.
- Separate duties that can be dangerous together (e.g. transaction placing and clearing should never be done by the same person).
- Treat employees fairly.
- Educate employees about policies and consequences.
5
Q
Name 3 ways to Detect insider threats
A
- Log, monitor and audit employee activity.
- Pay special attention to privileged users.
- Allow anonymous reporting of issues.
6
Q
Name 2 ways to respond to insider threats
A
- Termination procedures are essential.
* Keep all logs to support investigation.