Visible to the public A Theoretical Review: Risk Mitigation Through Trusted Human Framework for Insider Threats

TitleA Theoretical Review: Risk Mitigation Through Trusted Human Framework for Insider Threats
Publication TypeConference Paper
Year of Publication2019
AuthorsApau, M. N., Sedek, M., Ahmad, R.
Conference Name2019 International Conference on Cybersecurity (ICoCSec)
Date PublishedSept. 2019
PublisherIEEE
ISBN Number978-1-7281-5657-6
Keywordscyclic process, enterprise risk management activities, Human Behavior, human trust, insider threats, insider threats risk, on-going process, People Process and Technology, Personnel, potential employees, pubcrawl, risk management, risk mitigation, security of data, software engineering, Trusted Computing, trusted human framework
Abstract

This paper discusses the possible effort to mitigate insider threats risk and aim to inspire organizations to consider identifying insider threats as one of the risks in the company's enterprise risk management activities. The paper suggests Trusted Human Framework (THF) as the on-going and cyclic process to detect and deter potential employees who bound to become the fraudster or perpetrator violating the access and trust given. The mitigation's control statements were derived from the recommended practices in the "Common Sense Guide to Mitigating Insider Threats" produced by the Software Engineering Institute, Carnegie Mellon University (SEI-CMU). The statements validated via a survey which was responded by fifty respondents who work in Malaysia.

URLhttps://ieeexplore.ieee.org/document/8970795/
DOI10.1109/ICoCSec47621.2019.8970795
Citation Keyapau_theoretical_2019