Chapter 2. Insider Threats

 

“The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards.”

 
 --Gene Spafford

Understanding Who the Insider Is

I agree with Gene Spafford’s quote in this chapter’s title page, but only if the guards have been verified as trustworthy. As this chapter will address, insiders are unlike any other threat, and they force organizations to think differently about security risk.

I recall something that happened early in my career when I was conducting a security assessment for a hi-tech company in Northern California. One morning a part-time contractor who was providing this same company with system administration support was fired over the phone. Unfortunately ...

Get Enemy at the Water Cooler now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.