首页> 外文会议>International conference on nuclear security: enhancing global efforts >Insider Threats in Comparative Perspective: Lessons Learned from Past Mistakes
【24h】

Insider Threats in Comparative Perspective: Lessons Learned from Past Mistakes

机译:比较视角的内部威胁:从过去的错误中学到的教训

获取原文
获取原文并翻译 | 示例

摘要

This paper identifies six mistakes that security-conscious organizations have made that exacerbatedrninsider threat problems and created dangerous incidents: (1) Assuming that serious insider problems are NIMOrn(Not In My Organization); (2) Focusing only on malicious insider threats; (3) Forgetting that insiders can knowrnabout insider threat protection methods and therefore work around them; (4) Assuming that security rules arernfollowed (or forgetting there are rules about when it is okay to break rules); (5) Using “Red Team” exercises,rnbut forgetting that red teams and protection forces have insiders too; and (6) Assuming that Red Flags will bernread properly. The diversity and complexity of insider threat causes warns us to avoid “the myth of absoluternsecurity.” Serious prevention efforts should therefore always be supplemented with equally serious emergencyrnresponse and mitigation efforts.
机译:本文确定了六个具有安全意识的组织犯下的错误,这些错误加剧了内部威胁问题并造成了危险事件:(1)假定严重的内部人员问题是NIMOrn(不在我的组织中); (2)仅关注恶意内部威胁; (3)忘记内部人员可以了解内部威胁防护方法,因此可以采取措施; (4)假定遵循了安全规则(或忘记了关于何时可以打破规则的规则); (5)使用“红队”演习,却忘记了红队和保护部队也有内部人员; (6)假设红旗将被正确读取。内部威胁的多样性和复杂性导致警告我们避免“绝对安全的神话”。因此,认真的预防工作应始终辅以同样认真的应急响应和缓解措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号