Defending Against Malevolent Insiders Using Access Control

Dale W. Murray, Betty E. Biringer · Wiley Handbook of Science and Technology for Homeland Security · 2008

Abstract Determining the insider adversary potential or insider threat spectrum is the first step in designing or evaluating the effectiveness against insider adversaries of an access control system. An insider adversary has knowledge, access, and authority that is not available to the outsider adversary. The single malevolent insider, the most probable insider threat, may be active or passive, violent or nonviolent, and motivated by a broad variety of drivers. Access control allows authorized individuals into a secured area while preventing entry by unauthorized individuals. Two primary tools of access control, contraband detection and tamper‐indicating devices, are directed to thwarting insider adversaries as they are deployed in restricted areas accessible only to authorized and identified personnel. Additional elements of access control systems that reduce the likelihood of insider adversary success include entry/exit logs, antipassback features, two‐person rule enforcement, and compartmentalization. These features can deter, deny, or dramatically reduce the effect of the malevolent insider. The unique characteristics of the insider threat and the access control features that are likely to affect this adversary are discussed.

Read the paper · More papers on PaperTik