EEMCS

Home > Publications
Home University of Twente
Education
Research
Prospective Students
Jobs
Publications
Intranet (internal)
 
 Nederlands
 Contact
 Search
 Organisation

EEMCS EPrints Service


19963 Securing the Extended Enterprise: A Method for Analyzing External Insider Threat
Home Policy Brochure Browse Search User Area Contact Help

Nunes Leal Franqueira, V. and van Cleeff, A. and van Eck, P.A.T. and Wieringa, R.J. (2012) Securing the Extended Enterprise: A Method for Analyzing External Insider Threat. In: Strategic and Practical Approaches for Information Security Governance: Technologies and Applied Solutions. IGI Global, Hershey, USA, pp. 195-222. ISBN 978-1-46660-197-0

Cover

Full text not available from this repository.

Official URL: http://dx.doi.org/10.4018/978-1-46660-197-0

Exported to Metis

Abstract

In extended enterprises, the traditional dichotomy between insiders and outsiders becomes blurred: consultants, freelance administrators and employees of business partners are both ‘inside’ and ‘outside’ of the enterprise. As a consequence, traditional controls to mitigate insider and outsider threat do not completely apply to this group of individuals, and additional or improved solutions are required. The ISO 27002 security standard, recognizing this need, proposes third-party agreements to cover security requirements in B2B relationships as a solution, but leaves open how to realize them to counter security problems of inter-organizational collaboration. To reduce this gap, this chapter presents a method for identifying external insiders and analyzing them from two perspectives: as threat and as possible mitigation. The output of the method provides input for further engineering of third-party agreements related to non-measurable IT security agreements; we illustrate the method using a manufacturer-retailer example. This chapter also provides an overview of the external insider threat, consisting of a review of extended enterprises and of challenges involved with external insiders.

Item Type:Book Section
Research Group:EWI-IS: Information Systems
Research Program:CTIT-ISTRICE: Integrated Security and Privacy in a Networked World
Research Project:VRIEND: Value-Based Security Risk Mitigation in Enterprise Networks that are Decentralized, VISPER: The VIrtual Security PERimeter for digital, physical, and organisational security
Uncontrolled Keywords:Outsider, Insider, External Insider, Extended Enterprise, IT Security Agreement
ID Code:19963
Status:Published
Deposited On:30 January 2012
Refereed:Yes
International:Yes
More Information:statisticsmetis

Export this item as:

To correct this item please ask your editor

Repository Staff Only: edit this item