Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Thursday, July 15, 2010

URGENT: Looking for Public data, Statistics and Surveys about Insider Threats related to Misuses of User Accounts within Enterprises

I am urgently looking for public data, statistics and any information that provide a quantitative analysis of threats related to insider attack and misuses of employees’ user accounts (within organisations).

For example, I found a survey by Cyber-Ark – the annual “Trust, Security and Password” survey - where 400 IT professional (working for UK and US enterprises) were interviewed. This survey revealed that 33% of interviewed people had access to resources and data that was not relevant to their role, When asked if they would consider taking a form of sensitive data from their present employer if they ever left, over 85% said they would.

Other statistics of some interest: here, here and here.

I have been looking for this kind information on the web but so far I found only a few solid analysis of the problem and surveys. Just a lot of words and common sense statements …

I need this kind of information to add references to a set of reports aiming at exploring and analysing the impact of IAM automation on enterprise access management processes.

Any help, consisting in links and references to publicly available information, would really be appreciated.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

No comments: