Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Job of the week
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents.
Featured White Paper
Featured Book
The IT Career Builder_s Toolkit features market-focused skills and proven methods you can use to jump-start and advance your career.
Sign-Up for
IT Workplace
eNewsletter Delivered Weekly
Click here
Page 1 of 1

IT sabotage, work behaviour linked

COMMENT ON THIS ARTICLE

Workers who sabotage corporate systems are almost always IT workers who exhibit specific negative office behaviour, according to recent research.

That is the conclusion of the U.S. military in conjunction with Carnegie Mellon University’s Software Engineering Institute Computer Emergency Response Team (CERT) program, which together analyzed insider cybercrimes across a variety of critical industry sectors.

The research suggests that potential troublemakers should be easy to spot.

Nearly all the cases of cybercrime investigated were carried out by people who were “disgruntled, paranoid, generally show up late, argue with colleagues and generally perform poorly.”

According to the research, 86 per cent of those who committed cybercrimes held technical positions and 90 per cent had system administrator or privileged system access.

Almost half — 41 per cent — of those who sabotaged IT systems were employed at the time they did it. Most crimes, however, were committed by insiders following termination. Most incursions — 64 per cent — involved VPNs and old passwords that had never been terminated, highlighting a lack of security controls and gaps in their organizations’ access controls.

As a result, Carnegie Mellon has developed a methodology that it said can help detect insider threats as early as possible, involving management, IT, human resources, security officers and others who “must understand the psychological, organizational and technical aspects of the problem, as well as how they coordinate their actions over time.”

Quicklink 079297

COMMENT ON THIS ARTICLE

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Book Reviews

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.