The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Insider Behavior:

Author

Fariborz Farahmand & Eugene H. Spafford

Entry type

article

Abstract

There is considerable research being conducted on insider threats is directed to developing new technologies. At the same time, ex- isting technology is not being fully utilized because of non-technological issues that pertain to economics and the human dimension. Issues re- lated to how insiders actually behave are critical to ensuring that the best technologies are meeting their intended purpose. In our research, we have investigated accepted models of perceptions of risk and charac- teristics unique to insider threat, and we have introduced ordinal scales to these models to measure insider perceptions of risk. We have also in- vestigated decision theories, leading to a conclusion that Prospect The- ory, developed by Tversky and Kahneman, may be used to describe the risk-taking behavior of insiders and can be accommodated in our model. We discuss the results of validating that model with thirty-five senior information security executives from a variety of organizations. We also discuss how the model may be used to identify characteristics of insid- ers’ perceptions of risk and benefit, their risk-taking behavior and how to frame insider decisions.

Date

2009 – 6 – 15

Key alpha

Farahmand

Publication Date

2009-06-15

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.