The Three Categories of Insider Threats

Pierre‐Emmanuel Arduin · 2018

Computing is resilient, safe and secured through procedures, fragments of code and infrastructures with known, controlled and rational behavior. This chapter explains a categorization of the insider threats with which an organization will be confronted. The categorization of insider threats relies on two dimensions: whether the character of the threat is intentional or not, and whether its character is malicious or not. The chapter focuses on the different insider threats that arise from this categorization. The chapter exposes attack scenarios originating from unintentional insider threats. The taxonomy of threats targeting the security of information systems is with regard to the four dimensions: sources, authors, intentions and consequences. Independent of the sources, authors and intentions of an attack, the consequences remain the same: disclosure of profitable information, modification or destruction of crucial information, or denial of service by hindering access to resources.

Read the paper · More papers on PaperTik