Journal of Information System Security
Volume 13, Number 3 (2017)
Pages 151173
ISSN 1551-0123
Leung Chim — Defence Science and Technology Group, Edinburgh, Australia
Daniel Bilusich — Defence Science and Technology Group, Edinburgh, Australia
Steven Lord — Defence Science and Technology Group, Edinburgh, Australia
Rick Nunes-Vaz — Defence Science and Technology Group, Edinburgh, Australia
While it is known that the management of insider threats to information security requires the use of multiple layers of countermeasures, a holistic framework for designing and integrating the layers is missing. As a result it is often difficult to evaluate the overall effectiveness of a layered defence. In this paper we adapt a successful framework from physical security to support the design of insider threat security layers in a way that supports the evaluation of residual risks: a natural metric for gauging the overall effectiveness of a security program. When the insider threat is represented as a sequential pathway of insider activities and their consequences, security layers may be introduced to stop the attack or to nullify its impact in multiple ways. We find that the seven layer types from physical security all have analogous counterparts in insider security, and we provide examples using known countermeasures. The calculation of residual risk can then be performed using expert elicitation and stochastic mapping. We illustrate the method using a subset of the insider threat spectrum and assess the effectiveness of alternative (artificial) treatment packages. Note that the illustrative analysis is not intended to imply recommendations for particular solutions or approaches to the insider threat.




Holistic Framework, Information Security, Insider Threat, Integrated Security, Layered Defence, Risk Management




