Information Technology Architecture and Insider Computer Fraud Prevention
Kenneth Brancik · Auerbach Publications eBooks · 2007
The components of an information technology infrastructure and its security risks and controls are unique to every enterprise and particularly noteworthy in terms of how an architectural framework is designed and deployed to identify and mitigate the risks associated with insider computer fraud (ICF). Many organizations have Internet facing Web-based applications that can be accessed remotely by the insider either within the confines of the organization or remotely. Conversely, there are many applications within organizations that are not network based or Web based and function as stand-alone applications, which can also be used to perpetrate computer fraud. Consequently, the risk exposure for insider abuse is significantly higher for organizations that have Web-based versus traditional applications that can be accessed only within the organization.