首页> 外文OA文献 >Insider Threat Security Reference Architecture
【2h】

Insider Threat Security Reference Architecture

机译:内部威胁安全参考架构

摘要

The Insider Threat Security Reference Architecture (ITSRA) provides an enterprise-wide solution to insider threat. The architecture consists of four security layers: Business, Information, Data, and Application. Organizations should deploy and enforce controls at each layer to address insider attacks. None of the layers function in isolation or independently of other layers. Rather, the correlation of indicators and application of controls across all four layers form the crux of this approach. Empirical data consisting of more than 700 cases of insider crimes show that insider attacks proved successful in inflicting damage when an organization failed to implement adequate controls in any of three security principles: authorized access, acceptable use, and continuous monitoring. The ITSRA draws from existing best practices and standards as well as from analysis of these cases to provide actionable guidance for organizations to improve their posture against the insider threat.
机译:内部威胁安全参考体系结构(ITSRA)提供了针对内部威胁的企业范围解决方案。该体系结构包括四个安全层:业务,信息,数据和应用程序。组织应在每一层部署并实施控制措施,以应对内部攻击。没有一个层是孤立地起作用或独立于其他层。相反,指标的相关性和控制在所有四个层中的应用构成了此方法的关键。由700多个内部犯罪案件组成的经验数据表明,当组织未能按照三种安全原则(授权访问,可接受的使用和持续监控)中的任何一种实施适当的控制措施时,内部攻击就成功地造成了损害。 ITSRA借鉴了现有的最佳实践和标准以及对这些案例的分析,为组织提供了可操作的指导,以提高其针对内部威胁的态势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号