Investigate the Insider Threat

microsoft office training cbt

Everyone prepares for the ‘outside threat’. The hacker who has nothing better to do with their time and energy. Or the security breach that finds a hole in your network and exploits it to their financial advantage. The internal threat, your employees pose a threat just as great if not more, as they know your system, they are full aware of how the business operates, and where your weak spots are located. That fact alone makes it very easy to violate the trust you placed with the employee. Equipment walks out the door, accounting and bookkeeping manipulation, data is stolen and sold to an outside source, and other methods of theft are a daily occurrence.

The audits and investigations you execute have to be well planned, and still protect the innocence of the good employees. You must be part detective, use soft skills, and also consider the legal ramifications involved. Your planning should include a concise policy of how internal investigations best practices are to be conducted. You want to protect the reputation of the business and avoid legal actions agains the company, avoid mistakes, and end up with the correct assessment.

Documentation is a must. Remaining in company compliance and policy in case you have to testify in court will protect you and the organization. Documentation also confirms your actions during the investigation.

Confidentiality is also important. Spreading the news of an investigation works against you, embarrassing the suspicious, and may bring harassment, intimidation and retaliatory actions against you and the company. Collected evidence should be protected and stored in a safe location, with minimal access by individuals who have no reason for access.

Always perform interviews with a team. This provides more than one witness, and allows team members to complete tasks, such as one person asking questions while another performs the note taking duties. Obtaining a written statement decreases the chance of mistakes in what was said, and provides an excellent source of ammunition for prosecutors. Other departments may be called upon to lend assistance, including Human Resources, IT information security, building security, legal department, any managers connected to the suspect, forensic specialists, and more.

The evidence of wrong doing includes any expense accounts, time cards, personnel files, computer data, phone records, time sheets and cards, appointment schedules, hard drives, voice and email messages, and more. By all means, feel free to consult with legal counsel and gain approval before embarking on an investigation. Many areas may be out of your purview, including audits, surveillance, property searches, and monitoring. Software exists to detect missing or altered finances. Searches for abnormal changes, addresses that do not match vendors, invoice numbers that have been altered or compromised are only a few of the many warning signs. Utilities to aid in forensics are available and can detect issues such as email abuse, fraud, mismanagement of funds, organizational data that has been compromised, theft, and other areas. There are even utilities that can recover erased records and deleted information.

There are many other abilities that come into existence in an investigation, including interviewing techniques, spotting lies, reading body language, and much more. CISSP training courses in information security is a necessity and should be pursued in order to retain a certified professional on staff, in the workplace. K Alliance training has courses such as these, and so many more.

Do not underestimate the growing threat of insider theft and security. Breaches arrive in many forms, and from many directions. Make sure you are one of the prepared.

About Us: Office Training CD specializes in a superior collection of Microsoft Office 2010 training courses. Microsoft SharePoint WorkSpace training courses presents the advantages of using the advanced capabilities of a great collaboration solution. Business intelligence is important to your company, and Office Training CD includes customized development to satisfied your training requirements. The computer based training of Office Training CD is your location for expert training in all things related to Microsoft Office.