Evaluating and managing the integrity of computerized accountability systems against insider threats
Jones, E., Alan Sicherman · University of North Texas Digital Library (University of North Texas) · 1996
Accountability applications such as nuclear material accountability systems at Department of Energy (DOE) facilities provide for tracking inventories, documenting transactions, issuing periodic reports, and assisting in the detection of unauthorized system access and data falsification. Insider threats against the system represent the potential to degrade the integrity with which these functions are addressed. While preventing unauthorized access by external threats is vital, it is also critical to understand how application features affect the ability of insiders to impact the integrity of data in the system. Aspects of modern computing systems including powerful personal computers and applications on networks, mixed security environments, and more users with increased software knowledge and skills help heighten the concern about insider threats. A question arises as follows. How can managers and policy makers logically and pragmatically analyze the myriad customization and design options for accountability applications with respect to the insider threat. In this paper, we describe a methodology for addressing this question, along with insights from its application to local area network (LAN) material accountability systems.