Insider Threat Program as an Auditor

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
or

Already have an account? Sign In »

Time
36 minutes
Difficulty
Intermediate
CEU/CPE
1
Video Transcription
00:06
Yeah,
00:10
one of the most valuable aspects of an insider threat program or I t. P is the visibility it provides into so many areas of your organization
00:21
and optimized insider threat program will be the flashlight illuminating the dark corners of your company. Alex No.
00:31
Sorry.
00:34
Okay, that sounds ominous. But what I'm getting at is your insider threat program should expose ah lot of activity that you may have previously been unaware of and unable to monitor.
00:48
In addition to configuring your program to address specific use cases, you can set up your program to assist mawr generally with visibility and discovery.
01:00
For example, where is the data going?
01:03
What cloud applications are employees using
01:07
which parts of the business access or use certain files?
01:11
As you compile data and metrics, you can compare it with the policies and processes in place to see how effective they are
01:21
and if your employees air following the guidelines. So let's hear from Peter Hodja Giorgio to illuminate these points. Alex,
01:32
we admit
01:33
the A word doesn't exactly generate a lot of excitement and enthusiasm.
01:38
But audits, whether external or internal, are a fact of life, especially in the field of cybersecurity.
01:45
Self auditing is important for a variety of reasons. Insider threat programs are often the subject of audits but rarely considered as a resource or facilitator for audit teams as it relates to a number of common corporate policies.
02:00
There are a number of common policies associated with data security.
02:04
Use of cloud applications is a great example, and increasingly relevant has so many organizations and their employees transition toe work and life in the cloud
02:14
your organization may have a set of approved cloud collaboration or cloud storage. APS.
02:20
Hopefully, you have well documented policies that air clearly communicated to the workforce, that define exactly how employees should be using cloud APS for work purposes.
02:30
But then what?
02:30
How do you know who's following that guidance?
02:34
How do you audit adherence to that policy?
02:38
Enter your friendly insider threat program team
02:40
with the right tools and configurations. The Insider Threat program can tell you exactly who is using sanctioned or unsanctioned cloud APS and what data they're putting in those APS.
02:51
We encourage you to put your insider threat program to the test
02:54
Canada assists with this type of audit request.
02:58
If you're asked to report out how many users are moving data to USB personal emails or cloud. Can you help
03:06
as a side note? If any of these policies aren't implemented in your organization,
03:10
work with your legal in HR teams to put some new or updated policies in place.
03:16
This type of policy or process audit isn't typically associated with an insider threat program, but when you think about it, using your I t. P like this is an excellent way to improve the perception of the program and get buy in from a variety of stakeholders in the organization.
03:36
For example,
03:37
while HR teams are rightly sensitive to privacy or culture concerns around an insider threat program,
03:44
they may realize the benefits of the visibility your program offers and work with you to ensure compliance.
03:53
Because audits can be just another use case for your program, don't shy away from audit topics in an insider threat program.
04:01
Embrace them.
04:03
Ultimately, if your insider threat program can provide answers to audit questions, it provides validity for both the audits and the insider threat program.
04:15
Thanks for watching
04:18
that again.
Up Next