An assessment of opportunity-reducing techniques in information security: An insider threat perspective

作者:

Highlights:

• Evaluation of opportunity-reducing measures in information security

• Suggests that extant techniques are insufficient

• Evaluation derived may be used as a proactive mitigation strategy

摘要

This paper presents an evaluation of extant opportunity-reducing techniques employed to mitigate insider threats. Although both motive and opportunity are required to commit maleficence, this paper focuses on the concept of opportunity. Opportunity is more tangible than motive; hence it is more pragmatic to reflect on opportunity-reducing measures. To this end, opportunity theories from the field of criminology are considered. The exploratory evaluation proffers several areas of research and may assist organizations in implementing opportunity-reducing information security controls to mitigate insider threats. The evaluation is not definitive, but serves to inform future understanding.

论文关键词:Insider threat,Situational Crime Prevention theory,Cybercrime,Delphi technique

论文评审过程:Received 13 September 2015, Revised 1 August 2016, Accepted 13 September 2016, Available online 19 September 2016, Version of Record 12 December 2016.

论文官网地址:https://doi.org/10.1016/j.dss.2016.09.012