Management and Education of the Risk of Insider Threat (MERIT): Mitigating the Risk of Sabotage to Employers' Information, Systems, or Networks

Abstract

The Insider Threat Study, conducted by the U.S. Secret Service and Carnegie Mellon University s Software Engineering Institute CERT Program, analyzed insider cyber crimes across U.S. critical infrastructure sectors. The study indicates that management decisions related to organizational and employee performance sometimes yield unintended consequences that increase risk of insider attack. The problem is exacerbated by a lack of tools for understanding insider threat, analyzing risk mitigation alternatives, and communicating results. The goal of Carnegie Mellon University's Management and Education of the Risk of Insider Threat (MERIT) project is to develop such tools. MERIT uses system dynamics to model and analyze insider threats and produce interactive learning environments. These tools can be used by policy makers, security officers, information technology and human resource personnel, and management. The tools help these users to understand the problem and assess risk from insiders based on simulations of policies, and on cultural, technical, and procedural factors. This technical note describes the MERIT insider threat model and simulation results.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2007
Accession Number
ADA468801

Entities

People

  • Akash G. Desai
  • Andrew P. Moore
  • Bradford J. Willke
  • Dawn M. Cappelli
  • Elise A. Weaver
  • Timothy J. Shimeall

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Biomedical
  • Cyber
  • Weapons Technologies

DTIC Thesaurus Topics

  • Computers
  • Cyber Threats
  • Cybersecurity
  • Department Of Defense
  • Education
  • Employment
  • Human Resources
  • Information Systems
  • Insider Threats
  • Management Personnel
  • Personnel Management
  • Psychology
  • Sabotage
  • Security
  • Simulations
  • Software Development
  • Students

Fields of Study

  • Computer science

Readers

  • Software Engineering.
  • Strategic Security Studies

Technology Areas

  • Cyber