What's changed: Initial version
4.1Human and physical controls
Covers organizational deterrence measures based on the internal-fraud-prevention guideline, security education via targeted-email drills and red team exercises, the need-to-know (least privilege) principle and privileged access management, log management, entry/exit control including anti-passback and interlock mechanisms, clear desk / clear screen policy, and RASIS, the metric set for system reliability.
Stacking technical controls alone will not prevent insider fraud or human error. As IPA's Guidelines for Preventing Insider Fraud in Organizations point out, insider fraud occurs when "motive, opportunity, and rationalization" align. This section studies human and physical controls from the perspective of a security officer at a company who must decide how to combine measures to reduce the risk of insider fraud.
4.1.1Internal fraud prevention guideline and security education
- IPA's Guidelines for Preventing Insider Fraud in Organizations center on "denying opportunity" and "breaking the fraud triangle (motive, opportunity, rationalization)," calling for multifaceted measures spanning asset management, access control, physical management, personnel management, and compliance. They work only in combination with organizational operating rules, not technical controls alone.
- Security education and drills include targeted-email training (sending simulated attack emails and measuring open/report rates to raise awareness) and red team exercises, in which a simulated attacker team tries to slip past the organization's defenses to test the defending blue team's real-world response capability in a practical, hands-on way that classroom training cannot provide.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

