Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Technical Report

Common Sense Guide to Mitigating Insider Threats, 5th Edition

  • Abstract

    This fifth edition of the Common Sense Guide to Mitigating Insider Threats provides the most current recommendations of the CERT® Division (part of Carnegie Mellon University’s Software Engineering Institute), based on an expanded corpus of more than 1,000 insider threat cases and continued research and analysis. It introduces the topic of insider threats, explains its intended audience and how this guide differs from previous editions, defines insider threats, and outlines current patterns and trends. The guide then describes 20 practices that organizations should implement across the enterprise to prevent and detect insider threats, as well as case studies of organizations that failed to do so. Each practice includes features new to this edition: challenges to implementation, quick wins and high-impact solutions for small and large organizations, and relevant security standards. This edition also focuses on six groups within an organization—Human Resources, Legal, Physical Security, Data Owners, Information Technology, and Software Engineering—and maps the relevant groups to each practice. The appendices provide a revised list of information security best practices, a new mapping of the guide’s practices to established security standards, a new breakdown of the practices by organizational group, a new look at considerations for employee privacy, and new  checklists of activities for each practice.

  • Download

Cite This Report

SEI

Collins, Matthew; Theis, Michael; Trzeciak, Randall; Strozer, Jeremy; Clark, Jason; Costa, Daniel; Cassidy, Tracy; Albrethsen, Michael; & Moore, Andrew. Common Sense Guide to Mitigating Insider Threats, 5th Edition. CMU/SEI-2016-TR-015. Software Engineering Institute, Carnegie Mellon University. 2016. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738

IEEE

Collins. Matthew, Theis. Michael, Trzeciak. Randall, Strozer. Jeremy, Clark. Jason, Costa. Daniel, Cassidy. Tracy, Albrethsen. Michael, and Moore. Andrew, "Common Sense Guide to Mitigating Insider Threats, 5th Edition," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Report CMU/SEI-2016-TR-015, 2016. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738

APA

Collins, Matthew., Theis, Michael., Trzeciak, Randall., Strozer, Jeremy., Clark, Jason., Costa, Daniel., Cassidy, Tracy., Albrethsen, Michael., & Moore, Andrew. (2016). Common Sense Guide to Mitigating Insider Threats, 5th Edition (CMU/SEI-2016-TR-015). Retrieved February 22, 2017, from the Software Engineering Institute, Carnegie Mellon University website: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738

CHI

Matthew Collins, Michael Theis, Randall Trzeciak, Jeremy Strozer, Jason Clark, Daniel Costa, Tracy Cassidy, Michael Albrethsen, & Andrew Moore. Common Sense Guide to Mitigating Insider Threats, 5th Edition (CMU/SEI-2016-TR-015). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2016. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738

MLA

Collins, Matthew., Theis, Michael., Trzeciak, Randall., Strozer, Jeremy., Clark, Jason., Costa, Daniel., Cassidy, Tracy., Albrethsen, Michael., & Moore, Andrew. 2016. Common Sense Guide to Mitigating Insider Threats, 5th Edition (Technical Report CMU/SEI-2016-TR-015). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738

BibTex

@techreport{CollinsCommonSense2016,
title={Common Sense Guide to Mitigating Insider Threats},
edition={5th},
author={Matthew Collins and Michael Theis and Randall Trzeciak and Jeremy Strozer and Jason Clark and Daniel Costa and Tracy Cassidy and Michael Albrethsen and Andrew Moore},
year={2016},
number={CMU/SEI-2016-TR-015},
institution={Software Engineering Institute, Carnegie Mellon University},
address={Pittsburgh, PA},
url={http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=484738} }