Insider Computer Fraud (ICF)
Kenneth Brancik · Auerbach Publications eBooks · 2007
Listed below are the primary accomplishments of this book, listed by its contributions to the discussion of specific topics: 1. The Insider Threat Strategic Planning Process: a. The development of the tailored risk integrated process (TRIP) used for identifying business and technology risks. b. An approach for completing a privacy impact assessment (PIA). c. Application criticality. d. Qualitative and quantitative risk ratings. e. Residual and net residual risk (NRR). f. The Defense in Depth Security Efficiency Calculation. g. An integrated internal and external threat modeling process. h. Developing data flow diagramming and the determination of a key risk indicator (KRI), the critical path. i. Calculation of the Defense in Depth Efficiency Calculation to assess the effectiveness of layered security. j. The use of security patterns in identifying and resolving InfoSec problems. 2. Enterprise Architecture: a. A high level of understanding of the various information technology (IT) infrastructure components as an important layer in the Defense in Depth Security Model.