Book Review: The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud) (2012) by Dawn M. Cappelli, Andrew P. Moore, and Randall F. Trzeciak
Executive Summary The authors have reviewed more than 700 cases of insider threat attacks and developed a comprehensive list of mitigation controls that might have prevented them. The book is not very well organized, but the content represents the authoritative source on precursor behavior that may illuminate potential insider attacks. In that regard, it is a must-read for cyber security professionals. What is clear from reading the book is that there is no technical solution that will prevent insider attacks. Technology can aid in discovery, but it is not a panacea; it will not prevent a determined inside attacker. A good program will accomplish four tasks: Train employees and their managers to watch for the signs of potential insider threat behavior. Provide the mechanisms across the organization to report and review the activity. Establish and maintain the apparatus to report potential abuse and respond to incidents when necessary. Mitigate the risk before any damage...