Reference no: EM133985094
Question
Insider threats describe security threats to an organisation coming from people working inside the organisation. As the CISO (Chief Information Security Officer) of an organisation, you are aware that insider threats are an increasing exposure for all organisations.
For each of these insider threats listed below:
a) identify controls that could reduce the risk the threat occurring (prevention);
b) identify controls that would assist with the detection of these threats, should they occur.
The solutions can use some technology, but the human factor is also important in addressing these issues. The solutions shouldn't prevent the normal work of the organisation from occurring.
1. An IT systems administrator uses their privileged access to insert some additional (ghost) staff members on the payroll system and then collects the pay of these ghost staff members;
2. A member of a University student administration area with access privileges to update grades in the student records system has been taking bribes from students to modify their grades for important units. Note that the normal workflow involves grade modifications being recommended by academics in charge of the relevant unit, the grade changes being approved by various processes, then entered into the student records system by a staff member in the student administration area.