Tuesday, September 10, 2019

Lack of Empowerment in Government Organization Essay

Lack of Empowerment in Government Organization - Essay Example In an organization, empowerment is a broad perspective of dealing with its culture, leadership, practices and employees. In this paper, lack of empowerment effects on employees and stakeholders of organization ABC is looked at critically. This will entail organizational structure stability, employees’ satisfaction and job security and performance evaluation and reward structure. The report will conclude by trying to recommend solutions and courses of action to treat or work around this problem. Objective and research question Objective of the paper is to analyze â€Å"lack of empowerment’s† effects to Government Organization (ABC). Research question: What are the effects Organization ABC faces for lack of empowerment implementation? This is the guiding principle for this paper ensuring that the paper analyzes the effects of â€Å"lack of empowerment† to the organization. Definition of the Problem The problem of â€Å"lack of empowerment† within government organization (ABC) was identified through a survey conducted by the Human Resources Department to assess the levels of employees’ satisfaction.The survey showed that many employees felt they were unsupported by their managers, and that they were not given the chance to make decisions, even at very low levels. The results of the survey were analyzed and most of the negative responses were established to be correlated to lack of empowerment.... The report will conclude by trying to recommend solutions and courses of action to treat or work around this problem.   Objective and research question Objective of the paper is to analyze â€Å"lack of empowerment’s† effects to Government Organization (ABC). Research question: What are the effects Organization ABC faces for lack of empowerment implementation? This is the guiding principle for this paper ensuring that the paper analyzes the effects of â€Å"lack of empowerment† to the organization. Definition of the Problem The problem of â€Å"lack of empowerment† within government organization (ABC) was identified through a survey conducted by the Human Resources Department to assess the levels of employees’ satisfaction. The survey showed that many employees felt they were unsupported by their managers, and that they were not given the chance to make decisions, even at very low levels. The results of the survey were analyzed and most of the neg ative responses were established to be correlated to lack of empowerment. This was Employee Opinion Survey (EOS) thus the results are valid and credible since reflect employees responses. The problem was linked mainly to the organizational structures adopted by the public sector organizations, which can be characterized as centralized, hierarchical through the divisional and departmental structures, bureaucratic, with vertical communication lines. This in turn was reflected in many different forms like wasted time and effort required going through the proper communication channels, as well as friction between organizational departments. The problem of â€Å"lack of empowerment† also had drastic impacts on

Monday, September 9, 2019

Reflective Paper over Franz Kafka's Metamorphosis Essay

Reflective Paper over Franz Kafka's Metamorphosis - Essay Example He is very unhappy with his job and always narrates adverse effects of his job. He is made to do that job because of being responsible for his whole family. His room has three doors and also his family has three members, his father, his mother and his sister. Gregor Samsa is really unhappy with his life because of his overly responsibilities and his disdainful job. He comes back from his job and shuts himself in his room. The doors in his room are also to inform him about his responsibilities that he has in relation to his family members. Gregor Samsa himself likes to alienate himself from his family members because they are attached to him not as a source of attachment but with their own motives. Gregor wakes up one morning and sees him transformed into a big insect that is disdainful. Because of his transformation into an insect, he suffers through the problem of alienation physically. He is not only alienated from his family only but from the whole world because of his existence as an alien that is frightful. Initially his sister Grete shows some sympathy with him but with the passage of time, she also draws away from him. After his transformation, all his family members started their own jobs. Gregor Samsa is alienated from his family because of his gruesome existence. Anyone who sees him is at once frightened because of his transformed structure. He is also left alone to die and he dies in isolation after which, he is thrown out by his housemaid. His family becomes relieved at his death because they are not required to face people in relation to their son. They consider the existence of Gregor Samsa as a burden on them. Gregor is alienated because he has attachments not based on love and care but based on responsibilities. His parents and his sister look towards him as a source of income that is there to fulfill their wishes. After his transformation, he is of no use for the family but becomes a burden for them.

Sunday, September 8, 2019

Cell phone Assignment Example | Topics and Well Written Essays - 1250 words

Cell phone - Assignment Example In this light, deciding not to buy the cell phones for children has its advantages and disadvantages. Also, deciding to buy cellphones for the students has disadvantages and advantages that ought to be considered. Those against the idea of cells for students argue that they are disruptive and affect their concentration. On my part, I support the idea of equipping the students with the cell phones. There are several reasons for this stand that cannot be overlooked. For instance, the cell phones provide an easy channel of communication between parents and their children. In this light, the gadgets help ensure that parents can check on their children when they are not around. Secondly, I believe that the use of cellphones among the children from an early age helps open up their minds and increases the chance of innovation and the invention of technological gadgets. Moreover, the cell phones provide a source of leisure for the students and are crucial for their growth and development. However, this point may be invalidated on the basis that cell phones cause disruption among the pupils. Another point in support of cellphones for school-going children is that they help the students to research and learn new things through the Internet. The case study explains the effects that the cell phones have on students in Uganda who area allowed to use the cells not only at home but also in school. In the research conducted by Richard and his subordinates, the school allows students to carry their phones to school. According to the study, the availability of cellphones is a source of security for the students, which in turn helps boost their classroom confidence (Twebaze and Richard 23). Moreover, the students involved in the case study argued that keeping close contact with their parents at home helped give them the motivation to work hard. Richard adds that â€Å"cell phones not only allow the students to talk to their parents but also gives them a chance to expand

Saturday, September 7, 2019

Globalization Essay Example | Topics and Well Written Essays - 2000 words - 3

Globalization - Essay Example First, a firm may choose FDI rather than exporting when it wants to regulate cost uncertainty, as well as demand uncertainty. Through FDI, the international firm will meet the shifting local demand more quickly than when the firm uses exporting; this will improve the profits of the firm. Therefore, the firm may decide to internationalize business activities through FDI rather than exporting when the cost uncertainty is lower than the demand uncertainty. Moreover, firms that engage in the production of products that may be less similar may choose foreign direct investment as an entry strategy in foreign markets than the use of exporting. Another circumstance that may prompt a firm to use foreign direct investment rather than the other methods like exporting includes government policies. These may entail policies that discourage exports as a way of conducting international business. For example, nontariff as well as tariff barriers may discourage firms from choosing to export as an entry mode in international business. High taxes that may be levied on the exports may compromise the profits of the business enterprise. As a result, firms may choose to make direct investments in the foreign markets with an aim of maintaining productivity and profits. Tariffs may act as barriers to international trade, especially when firms depend on exports as a mode of entry in international markets. Another circumstance that may make a firm make a direct investment in a foreign country through FDI includes marketing concerns. This may entail the distribution, logistics, image of the firm, and responsiveness to the customers' needs. Firms that require quick and immediate feedback from the customers tend to choose FDI as the mode of entry in international markets (Markusen 2004, p. 287). Through FDI, the firm takes advantage of its presence in a foreign market to engage in widespread marketing of the products, which it produces. Thus, Foreign Direct Investment could be more favorable than exporting, licensing, and franchising in a situation where the firm wants to engage in enormous marketing of its products (Moran 2002, p. 100). Firms may also decide to internationalize their business activities through foreign direct investment where logistical considerations play an essential role in the activities of the firm. An example includes the costs attributed to internationalization th rough exporting (William 2004, p. 246). While firms decide to internationalize through exporting, some costs such as packaging, warehousing, distribution, and transporting costs will be incurred. Thus, in circumstances where firms want to avoid these costs, it will be more

Friday, September 6, 2019

Race and ethnicity in the United States Census Essay Example for Free

Race and ethnicity in the United States Census Essay The media is an industry where the competition is intense and it has been used by the government individuals, organizations, institutions, society, and family etc. for various purposes. However, due to the increasing competition in the industry, many at times the functions and duties which the media owes to the society are significantly overlooked. There are various functions of the media some will be discussed later on in this paper. The aim of the media has to a fearfully large extent shifted from fulfilling its roles to the society, rather their focus is often on how much entertainment they can offer to their audience and how much money they can make and how quickly they can make it. Entertainment and money making is definitely key in the existence, survival and growth of this industry, nevertheless, this should not be achieved by inappropriately portraying a group’s identity in any form. DEFINITION OF KEY TERMS Construction – To make or create, by putting together ideas, components or arguments. Group Identity – This refers to a person’s sense of belonging to a group. Media- Are communication channels through which news, entertainment, education, data or promotional messages are disseminated. Media includes every broadcasting and narrow casting medium such as newspapers, magazines, TV, radio, billboards, direct mail, telephone, fax and internet (business dictionary, 2015). THEORETICAL FRAMEWORK SOCIAL IDENTITY THEORY BY TAJFEL TURNER (1979) This theory was propounded in order to understand the psychological reasons and basis for inter- group discrimination. The components of this theory goes thus: Categorization- This is the process of putting ourselves and others into categories, our self-image is associated with the categories we belong to. Identification – This is the process by which we associate ourselves with certain groups of people. Nevertheless there are some groups we don’t want to be identified with (out groups) and there are some we would want to be identified with (in groups). Comparison- This is the process through which we compare our groups with other groups, thereby creating a positive bias towards the groups in which we are members of. This aspect of this work will focus on two salient functions of the media amidst the various ones there are. Social heritage function- The onus lies on the media to transmit positive racial and ethnic values about every existing race and ethnic group. The act of highlighting and spotlighting the various negativities of races and ethnic groups should be avoided. Surveillance function- This is the duty the media owes to the society in circulating news and information when necessary, the media is responsible for providing information about events. THE CONSTRUCTION OF GROUP IDENTITY BY HOLLYWOOD (A STUDY OF THE LATINO RACE) There are five acclaimed races in the world: 1) Mongoloid (Asian and American Indian) 2) Caucasoid (European) 3) Australoid (Australian and oceanic) 4) Negroid (East African black). 5) Capoid (South African black) The Latinos could be said to belong to the Mongoloid race and most of the 315 million people who live in the United States of America are either immigrants or have ancestry to another country. In actual fact, the only truly American people are the Native ones. This country is based on the idea of migration in pursuit of a better social and economic life. According to U. S. Census Bureau (2012), there are roughly 52 million Hispanics/Latinos living in the United States, representing approximately 16. 7% of the total population of United States of America, and making them the nation’s largest ethnic minority. Among Hispanic subgroups, Mexicans rated as the largest at 63%, followed by Puerto Ricans (9. 2%), Cubans (3. 5%), Salvadorans (3. 3%), Dominicans (2. 8%), and the remaining 18. 2% were Colombians, Guatemalans, Portuguese, Honduras, Ecuadorians, Peruvians, Brazilian. The main reason for their migration has been either that they are politically endangered or have financial problems. For instance the Cubans who ended up in America wanted to escape from the political conditions in their country. Escaping from the communist government practiced in Cuba, they were considered as ‘political refugees’ in America for three and a half decades until 1995. As a result of America’s opposition to the Cuban government, they were treated in America better than almost any other ethnic group. This has also been partly because of their high level of education and professionalism before migration (Martins, 2006 as seen in Mousavi Sadeghi, 2013). Latinos, Mexicans in particular, mostly live in the Southwest; almost half in California and Texas. Puerto Ricans are mostly in the East and Cubans are in Florida. According to the U. S. Census Bureau, legal Hispanic household income is only 75 percent of White American income. There is also a high rate of poverty and unemployment among them, and their socio economic status is at a low level. The cause for this situation is partially their jobs being the lowest paid ones, their low education level, and employment discrimination (Camarillo and Bonilla, 2001). They are present in the news, advertisements, election campaigns, political debates, television and films. The common major feature that is present in all of these portrayals is the problems related to them that should be solved and not to be glorified, exaggerated or exploited by Hollywood. Before now African Americans were more likely to be portrayed as domestic workers in Hollywood. African Americans played major roles in television sitcoms such as â€Å"Beulah† in the 1950’s and â€Å"Gone with the wind† in 1939. In recent times Latinos have increasingly replaced African Americans as Hollywood domestics. Hollywood has presented an incorrect reality of the Latino people to the American people and to the world at large, it has exaggerated a poor image of this particular race. Although the Latinos who live in America get more roles to play in Hollywood, most of these roles are mentioned in the next paragraph. The Latino female is often presented as a temptress, vamp, lustful, promiscuous, unfaithful, manipulative, of loose morals or submissive at times in relation to a white male fantasy, low class, serving the whites. A list of Ten Latino Female artists who have played the role of a maid in Hollywood Movies/series. Jennifer Lopez – Maid in Manhattan, 2002 Aida Linares- Clueless, 1995 Lupe Ontiveros- As good as it gets, 1997 (She has played an estimate of 150 maid roles on television). Consuela-Family Guy, 2005-till present Nadine Valesquez-My name is Earl, 2005-2009 Paz Vega- Spanglish, 2004 Kate Del Castillo- La misma Luna, 2007 Adriana Barraza- Babel, 2006 Catalina Saavedra, The maid, 2009 Roselyn Sanchez, Devious Maids, 2013- till present Pania Ramirez – Devious Maids, 2013 till present THE MEDIA, DIVERSITY AND SOCIAL CHANGE INITIATIVE (MDSCI)’S SIX YEAR STUDY REVEALS SOME STATISTICS. Among the racial and ethnic groups studied in the Media, Diversity, and Social Change Initiative’s report, released August 2014, Latinos made up only 4. 9% of movie characters across 100 of 2013’s top-grossing films. According to the U. S. Census Bureau’s estimates, there are roughly 52 million Latinos in the U. S. as of July 1, 2011, or just over 16% of the current U. S. population. That number is on track to reach 132. 8 million — or about 30% of the U. S. population — by July 1, 2050. LATINOS THAT ARE DEPICTED IN TOP-GROSSING MOVIES ARE MOSTLY NAKED. While the study does note that â€Å"Hispanic females (37. 3%) were more likely to be featured in popular films than were white females (29. 6%) or Asian females (32%),† Latinas are also more likely than females among any of the other groups studied (37. 5%, to be precise) to be shown partially dressed or nude on the big screen. LATINOS ARE ALSO HIGHLY LIKELY TO BE SEXUALIZED. The sexualization of Latinos does not stop with women. Latino men were the most likely among the studied groups (16. 5%) to be depicted wearing â€Å"tight, alluring or revealing clothing. † DANGERS OF THE NEGATIVE PORTRAYAL OF RACE ETHNICITY BY THE MEDIA ? Since there is a tendency to believe what is represented or depicted by the media; as particular races or ethnic groups are often negatively portrayed, others who are not acquainted with such group of people are bound to believe they are actually the way the media has presented them. ?Another danger of negative portrayals of race/ethnic groups by the media is that the younger ones from such groups may not be able to see themselves better than the way the media has portrayed them. For example if a race is continually depicted as a maid or as vulgar murderer the younger generation of such groups may not see anything wrong with being that way and could actually end up as same. ? This particular race have existing challenges of employment, poor education; the continuous depictions as such does not help solve these problems, but only worsens them. ?It could be difficult for people who are negatively portrayed to keep relationships with or amongst other races who are depicted as superior to them. THE NOLLYWOOD CONSTRUCT OF ETHNICITY (A STUDY OF THE YORUBA, AND NORTHERN NIGERIANS) The founding fathers of Yoruba films in Nigeria i. e. Herbert Ogunde, Moses Olaiya (Baba Sala) Based their works on the constructive values of the Yoruba ethnic group without leaving their audience entertained. In recent times Nollywood has neglected the transfer of social heritage function in the production of Yoruba films. More often than necessary abusive statements, raining of curses and the invention of such and rascality has been synonymous with Yoruba films. The very rich Yoruba culture which the world could learn from is often being tarnished by our film industry. However there are various Yoruba producers who focus on spreading the positivity of the Yoruba culture i. e. Tunde Kelani, Tade Ogidan, Yinka Afolayan. Men from the Northern part of Nigeria are also often times portrayed as either a gateman or the security man of a well-established family. The character who could actually be Yoruba speaks like a man from the north to convince the audience that the gateman is a man from the Northern part of the Country. Little does Nollywood know that many of the gatemen in Lagos which I can speak for are not even Nigerians. I have observed that most of the gatemen/security men in reality are actually from Niger Republic many of them look like Nigerian Northerners, are able to speak Hausa language but they are not Nigerians. RECOMMENDATIONS ?Every race has some sort of value and norms that could be positive, the media should hereby seek out such and spread them. The media needs to respect the fact that every human person has dignity and should be portrayed as such. ?They never should never assume that a particular race or ethnicity is less than the other, regardless of the socio economic status of such groups. ?The media should seek to solve the challenges faced by some races and ethnic groups rather than exploit them. The media should be reminded that they are socially responsible to the society, thus they should be mindful of what they feed the society with.

Thursday, September 5, 2019

PESTEL analysis of the Chinese and German flooring industries

PESTEL analysis of the Chinese and German flooring industries Since 1979, China adopted an export-manufacturing strategy successfully following with Japan, Korea and Hong Kong. The Golden Bridge Co., Ltd is one of the beneficiaries. It was founded in 2007 with flooring as its main products. The product is of high quality by utilizing advanced technology and equipments imported from Germany and Italy. The glue and lacquer materials for production are also imported. In current stage, Golden Bridge has a total capital of 800 million RMB and exported to 35 foreign markets including the U.S., Canada, Japan and Germany. In order to help it to expand the business, our consultancy company attempt to analyze the China business environment and seek a foreign market to relocate the manufacturing of this company with proper entering and competing strategies. This essay first illustrates the business environment of flooring industry in China and German with PESTEL analysis. Then it evaluates the threats in Germany market by following Porters five-force mode l. Later a recommendation would be given on how to properly enter into the targeted country. PESTEL analysis of china market: The PESTEL analysis is used to assess the macro environment and identify the challenges Golden Bridge faced with in china market in order to make an appropriate suggestion. Political: The Chinese political system characterized as one-party communist dictatorship makes a great contribution to national stability, enabling the economy keep dynamic and sustainable. Nevertheless, when the economic system was deregulated from the command economy to market economy since 1978, the power of economic management was increasingly decentralized, raising the issue of uncoordinated development of regional economy. Currently, though the central government has made effort to alleviate the gap among different areas in terms of developing standards, provinces tend to give a priority to local profits rather than considering the integrated advancement of the whole country. Local protectionism exerts detrimental influences upon market expansion of Golden Bridge Company in nationwide and deters the establishment of a comprehensive distribution channel. Economical: China is valued as one of the most vibrant countries in terms of economic development among the world. The reform opening up in 1978 accelerated Chinas GDP growth from 362.4 billion RMB to 30 trillion RMB within a 30-year period. Moreover, in 2010, China has been the second largest economy instead of Japan whilst the value of export accounted for 10% of world. Based on these statistics, judgment can be made that manufactures in China including flooring industry may keep an optimistic attitude to their future prospects in some extent. Nonetheless, Chinese economy may suffer unpredictable circumstance in the future. Labor resource is one double-edge sword. Once being an advantage of China, abundant labor resource and economical labor price make a great contribution to progress of those labor-intensive manufacturing industries. This is also the primary reason that China flooring industry is quite profitable though China is a net importer of timber. However, as cited by AME info (2005) there is a growth in the minimum wage standard, labor may not be regard as a perpetual advantage of China if this trend continues. In Addition, appreciation of CNY since 2005 against USD may imperil the export of Golden Bridge Company (Goldstein, M. and Lardy, N., 2006). Social: It is claimed by Su and Littlefied (2001) that China is an extremely high-context country where people prefer to receive implied messages. For establishing a business in China, strong private-relationships with different stakeholders is the key to success. However, this is extremely time-consuming while the maintenance is also expensive. Potential conflicts in interest may easily erode it. Besides the relationship, corruption is another issue in China. According to the Corruption Perceptions Index, China was positioned 72nd among all 179 countries in 2008. However, damages caused by corruption may be far more hazardous than anticipated, particularly to the economic development. Corruption has been treated as a vital barrier for operating in Chinese market due to enormous back-stage expenditures as well as resulted injustice. For Golden Bridge to gain more import quotas and pay less tariff, costs may be made up of not only normal ingredients such as transporting, but also implied expense for smoothing the network. Technological: China wood flooring industry is experiencing a relatively laggard technological standard in its initial stage of development. According to Cheng and Song (2006), the level of timber utilization was 61% in 2004 with a considerable disparity with developed countries (nearly 90%). Additionally, imbalanced technological support aggravates the long-term conflicts between wood supply and demand in Chinese domestic market. In 2004, though the total domestic timber supply is 273.6 million cubic meters and exceeded the total consumption of 241.5 million cubic meters, scarcity of raw material still existed in some parts of timber manufacturing industry. Environment Legal: Chinese government proposed the Natural Forest Protection Program (NFPP) nationwide in 1998 to limit exploitation of natural forest resources. The legislation made the supply of domestic natural timber restricted. Between 1997 and 2003, natural timbers supply decreased from 32.05 million cubic meters to 12.145 million cubic meters (Cheng and Song, 2005), which was extremely insufficient to satisfy demands of the highly prosperous timber industry in China. Timer manufacturing companies in China have to depend on importing. Statistics shows that in 1997 the quantity of imported timber only occupied 23.56% of total wood consumption, while the number soared to 53.78% in 2004. The expenditure of imported timber was $33.96 higher per cubic meter compared with the price in 2007, which increased the material coast of Golden Bridge Company. PESTEL analysis of German market: Since this essay has analyzed the macro environment of the china flooring market, further looking at the political, economic, social and technological factors of the German can help advance and strength the logic of the whole assessment. Political factors: Germany is a home of secure, legal and rewarding investment. The World Economic Forum has rewarded its legal system as the most efficient and this fact has also gained international recognition. Flooring coverings are categorized according to German and EU laws and building products should be subject to the EU construction products directive and the German construction products law. The directive and law are mainly focused on environmental, health-related, material and usability sectors and most people agree that by considering the environmental restrictions, the EU can be the strictest market. Moreover, with the transnational economic environment, it is predicted by experts that the approval criteria for flooring is likely to decrease and there seems to be a limited permission of eco-labels for flooring products. Further, comprehensive incentives  are provided to both home and oversea investors by German government, individual federal states and the EU. Economic factors Germany is the largest economy in Europe and in general German is export-oriented. Since 2003, German has been the largest exporter machinery, vehicles, chemicals and household equipment, with an annual export increase of 8%. However, factors that may prevent Golden Bridge from entering into and developing itself in Germany also exist. They can be excessive dependence on euro currency, tight credit markets and an increasing rate of unemployment. Stimulus and stabilization efforts initiated in 2008 and 2009 and tax cuts introduced in Chancellor Angela MERKELs second term will increase Germanys record budget deficit, which is expected to exceed 5% of GDP in 2010. The EU required Germany to get its consolidated budget deficit below 3% of GDP until 2013. A new constitutional amendment likewise limits the federal government to structural deficits of no more than 0.35% of GDP per annum as of 2016. Technology factors: Germany is claimed to be the leading nation in high-tech development and receives high turnover accordingly. In 2007, the high-tech products exported by Germany accounted to a value of RUR 114 billion, ranked first in Europe and third worldwide. More than 27% turnover of German manufacturing factory is generated from high-tech products, compared to a European average of 19%. Social factors: Social factors also need consideration. Hofstedes analysis of Germany shows the emphasis on individualism, masculinity and uncertainty avoidance. Power distance and long-term orientation are both ranked considerably lower than the others. Germany believes in equality and equal opportunity, as well as its ability to change and adapt rapidly. Another arising issue is the social awareness of pollution, which leads Germany to use more environmental-friendly materials. Abstract for the use of five-force model: After analyzing the macro-environment of both countries, it is reasonable and necessary to apply Michel Porters five-force model in order to provide a thoroughly understanding of the German flooring market before the Golden Bridge company entering into it. According to this model, the competitiveness of an industry is influenced by such five forces and their collective strength and thus determines the ultimate profit potential of this targeting industry. These five forces covered in the analysis are competitive rivalry, supplier power, buyer power, the threat of substitution and the threat of potential new entry. However, the five-forces framework is not a set of principals per se, instead is a tool for systematically use these principals to assess the current status and likely evolution of an industry. Competitive Rivalry: The internal competitive rivalry in German flooring market seems high. There are three main reasons. First, the switching cost is low because flooring products are homogenous with little product differentiation. Another reason is that the German flooring market is saturated with a relatively low growth rate. The flooring production in 2008 suffered a 15.1% decline while the total consumption slumped for about 12.19% (FEP, 2008). Also the number of competitive companies in German flooring market and the intensity of rivalry also determine the high threats of rivalry. There are a large number of companies competing in the German flooring market and these companies are divided into three categories, they are Small and Medium Sized Enterprises (SMEs), Domestic Leading Manufacturers (DLMs) and Niche Market Brands (NMBs). First of all, SMEs has the largest number in the German flooring market (Roadmap, 2010). These SMEs are often manufacturers provide low-grade flooring with low price. Their marketing strategy is just reverse to Golden Bridges. Thus Golden Bridge is suggested to treat them in an abstemious way. However, there are also a few numbers of large flooring manufacturers who operating on European and/or global base. It is suggested by German Timber (2007) that few DLMs account for the majority of the total market share. These companies usually possess strong competencies, highly recognized reputation and well-established brand image. One main rivalry is the Krono Group, who is one of the world leading producers of high-quality flooring. Founded in 1897, it has accumulated years of experience and extensive knowledge know-how. It delivers products to 80 countries worldwide while has its own production-base in 18 countries. In 2004, its production capability of flooring reached 310 million à £Ã … ½Ã‚ ¡, took up about 1/3 of the world market share with total sales revenue of 24 billion RMB. It also has an annual RD investment of 15billion RMB with over 200 scientists doing research in Krono International Laboratory. In addition, there are Niche Market Brands (NMBs) with several well-known brands like Espirt and Kaindl, holding part of the flooring market (FEP, 2007). These companies merely provide certain kinds of flooring to meet the special needs of a group of customers. Furthermore, in order to gaining competitive strength, the NMBs together with some foreign brands such as Balterio from Belgian and Vito from Austria have formed a conglomerate named Beamy International, a commercial platform allowing them to compete on both domestic and global markets (FEP, 2008). As the competition is fierce in German flooring market, Golden Bridge is suggested to adopt a niche strategy and doing effective promotion after entering the market. To explain, the original German wood flooring manufacturers already gains economy of scales and undeniably enjoy a cost advantage. Advanced distribution channel comparing with those new entrants also allows them first mover advantages. Cost disadvantage and lacking reliable cooperators are main barriers for Golden Bridge to survive in German market. Insufficient in capital determines that an aggressive expansion strategy is also irrational. However, one advantage Golden Bridge occupies is that it has been doing export business within German importers for couple of years and its products did have certain reputation in this highly competitive market. By offering additional value, Golden Bridge can efficiently differentiate itself among the rivals with a brand image of reliability, valuable, and symbol of statuses. This may help obtain sustainable brand loyalty among German customers. Threat of Substitutes: The threat of substitution refers to the extent to which different products used in place of a companys products or offered by other industrials. Flooring is not restricted on only wood but other materials such as textile and stone/ceramics are also widely used. For instance, in German market in 2008, textile took the largest raw material market share (i.e. about 37.4%) for making flooring. This is followed by stone/ceramics of 28.6%. Comparably, the laminate only had a market share of 13.9%, ranked in the third place. In terms of switching cost, the result can be distinct regarding to different objects of study. To individual consumers, there is almost no switching cost exists because choose one kind of material instead of another is just a matter of personal taste. However, this can be criticized in depth for the reasons that wood-made flooring has its own characteristics and functions that other materials may not have. To some extent and to specific customer groups, for instance, those who have fixed-decoration style, the switching cost can be relatively high. However, to large wholesalers (e.g. Beamy International) who previously dedicated in wood-made flooring, the switching cost would be extremely high, as they may lose the stable distribution channels with their current wholesalers or retailers, and also the price advantage provided by the long-term cooperative producers. This means the substitution threat is less considerable because their past investment in developing stable distribution channels with retailers and producers offers them an advantage in current market and this may make them unwilling to undertake risks of operating and competing in a new and highly competitive market. Summing up the above, it is the end-user customers that Golden Bridge should pay close attention to. First of all, it is advised that a regular customer survey to be conducted to make a comprehension of customers preferences and what they really appreciate. The company should also emphasize the exclusiveness and unique utilities of their products, making it cost more for the customers to switching to other substitutes. In the meantime, though as mentioned the future trend seems favor wood flooring industry, Golden Bridge should cause enough value that the technology development is always indeterminate. Thus in order to avoid sudden shock of new technologies that brings in comparable substitutes, Golden Bridge should invest continuously in Research and Development to keep pace with the times. Threat of New Entrants: Threat of new entrants is moderate. As put by European Commission (2001), the main barriers to enter German market include certification approval and the quality standards and label, while the incentive to enter German market depends mainly on its impeccable infrastructure system. The extensive unified intensification, which has been mentioned before in PEST Analysis of German, increase the starting investment of new entry, accordingly has negative effect on new entrants to the market. There are totally fourteen member countries of European Federation of the Parquet Industry (FEP). Under the Single European Market policy, twelve of them have reached an agreement on moving goods, service and capital freely internally, giving companies in these markets strong mobility. To put it simpler, a flooring company located in Germany for example, can either choose to develop domestically or entre into either of the other 11 member countries of EFP, in support of the unified system. Once entering into the consolidated FEP, the new members deserve this privilege with little hindrance, however, the legal entry requirement, especially for flooring companies compliance with environmental protection, is said to be quite strict in European Market, which is especially true in Ge rmany. Thus it can be expected that in order to harmonize to European standards, a large quality of funds will be needed to invest in order to fulfilling the standards ranging from environmental protection to individual healthcare. What is more, the sophisticated infrastructures that Germany possesses nationwide make the market considerably attractive to those adventurous entrepreneurs. As known to all, Germany lays in the center of the Western Europe, with large-scale transportation centers such as International airport in Frankfurt and seaport in Hamburg (ELA, 2010). Centering in a fast and efficient logistic network covering almost all the main markets in Europe, flooring companies in Germany can procure raw materials namely timber on a global scale, and reach the external markets with relatively lower transportation costs. Therefore the threats of new entrants would be moderate in German flooring market. For Golden Bridge, the corporate should create a marketing and brand image and keep customers loyalty, tie up to both suppliers and distributors. More important, it should sign a patent to protect the intellectual property of their high-tech products. Buyer Power: Buyer power, which is determined by the individual customers ability in negotiating purchase prices with suppliers, is at an intermediate level in German market basing on four crucial reasons. Firstly, according to the previous analysis, competition in the wood flooring manufacturing is largely intensified by a large amount of incumbents. Hence, purchasers are more unrestricted in choosing their suppliers with considering competitive advantages of products, and price may be a decisive factor for some customers. However, it is important to note that Wholesalers have more bargaining power than individuals. Being the large-volume buyers, they are not only main customers where companies earn profits from, but also controllers of dominant distribution channels. By stark contrast, individual customers with smaller purchase volume may be positioned less vitally in suppliers minds. Secondly, the buyer power is attenuated by the availability of substitutes of wood flooring in German market. E xcept for this category of flooring, more choices are supplied on the market. Despite competition reinforces customers bargaining power, the phenomena of demand surplus in German wood flooring alleviates this circumstance. According to the research of European Federation of the Parquet Industry (FEP), the consumption of German wood flooring is about 17.88 million square meters, while the production of German wood flooring is only about 11.04 million square meters (Slides Stats 2008). In additionally, German culture also plays a significant role in lessening customers bargaining power. The spirit of the nation, such prudence and fixation lead to a fairly strict standardization in both work and life. Germans are used to calculating a precise price based on all dimensions. Hence, they dislike dealing with situations out of their planning, enabling bargaining become very difficult. Ten percentage cut in price is the biggest range they will agree in they dealing with foreign buyers. (LeMont Schmidt, 2001). Supplier Power: Supplier Power refers the power of suppliers to drive up the prices of raw materials, supplies, equipment or inputs. Your company purchases the glue, paint and equipment, and employs labors from Germany and imports the wood from Russia. There are some crucial factors performing low supplier power of your company. Firstly, German is not used to bargaining, which is mentioned in Buyer power. Hence, it is meaningless for German suppliers to drive up the price of material and equipment. Negotiating power is weak in Russia as well. Although the nation is one of the largest wood producers, there are a large number of wood suppliers ¼Ã…’which provide a strongly competitive circumstance in Russia. Admittedly wood is a kind of nature product so that customers are sensitive to the price of wood. Because of high standard of transparency, the switching cost is low in Russia. On the other hand, many substitutes with lower expenditures are becoming increasingly prevalent such as marble, carpet, plastic flooring. High standard of substitutes threat can restrict the suppliers to drive up the price and reduce the power of suppliers. However, high labor cost strengthens the supplier power. The German labor cost is one of the highest in world. According to Common Protocol of Salary, Labor wage need be determined by the negotiation between wood flooring industry and backwards industry (Fact about Germany, 1996). Therefore, the security of labor force is quite completed. Unions are powerful to argue with unfair wage or welfare. For example, Michael Sommer, the head of the trade union federation(DGB) , claimed that is necessary to increase labors wage with the upturn of economy in 2010( Guardian ¼Ã…’2010). Supplier power and buyer power, which exert a moderate threat on Golden Bridges development in German, can be alleviated through several ways. From one aspect, to limit bargaining power of large-volume wholesalers, the company should give priority to building up a distribution network itself by developing new franchisers rather than depending on the primary channels of wholesalers. In terms of individual customers as well as challenges from substitutes, enhancing the products benefits would be the most efficient way to reduce their bargaining desire as most of affluent people value quality more important than price. From the other aspects, labor relationship, the most considerable barrier in lessening German supplier power, should be harmonized through affording sufficient welfare to employees, as well as building a relative democratic organizational culture by the company. Moreover, it is supposed that importing a few skilled workers from China would benefit the company not only by more economical labor cost, but also reducing the significant dependence on the German labor market. Limitation of the 5-forces: Porters five-force model is not perfect but based on the assumption that from the view of any one firm, all the other firms no matter whether they are supplier, competitor or buyer are threats to the profitability. However, according to Brandenberger and Nalebuffs value net theory, interactions among firms can sometimes enhance profits. Thus critics raised and attentions on cooperation are much more paid. The cooperation between the Golden Bridge Company and other foreign flooring companies will be analyzed and evaluated in the later recommendation part. Recommendation By illustrating the German macroeconomic environment and its circumstance of flooring industry, it is thought that the most recommended strategy for Golden Bridge is to build a joint venture with one or several German covering floor manufacturing enterprises, whilst maintaining the manufacturing section and primary market system in China. Joint venture can be explained as a collaborative formation among companies that each party invests parts capabilities to constitute a new enterprise, thereafter determining the distribution of ownership according to corresponding contributions. Nevertheless, two preconditions should be taken into consideration before making an alliance with German incumbents. Firstly, as a dominant barrier in Chinese market, capital insufficiency would also limit the investment ability of Golden Bridge in German to a large extent. Consequently, small-to-medium incumbents are more desirable as cooperators rather than large-scale companies in terms of ensuring a rela tively high proportion of ownership of Golden Bridge in the new joint venture. Moreover, it is imperative to illustrate compatibility of potential partners based on a number of philosophic criteria, including similar experience, common principles and agreed future target as well (Kanter, 1994). Where extremely intensive competition takes place, German market would tend to pose more threats than opportunities on the Golden Bridge if the company attempts to entirely entry the market alone. In comparison, cooperating and aligning with local companies would be a much safer and efficient measure from two aspects. First, by giving joint ventures preferential treatment, the Golden Bridge gains a good opportunity to penetrate the German market in a relatively short period with minimum risks as the company is unnecessary to expose abundant long-term investments to gain market shares in German wood flooring industry. Instead, it can utilize those important strategic assets of local cooperators such as complete distribution channels, customer relationships and brand loyalty. Moreover, Golden Bridge is still deficient at technology and management comparing with the local German companies. Through setting up a joint venture, advanced technology and managerial know-how can be more easily accessible by Golden Bridge, which is beneficial to its development in China market as well. Nevertheless, possible issues relating to joint venture cannot be neglected by the Golden Bridge. First, operational dissimilarities caused by political and economic divergence between China and German may be a vital problem for Golden Bridge. For instance, blind spots in law or financial systems will damage the corporate profits at initial stage. Additionally, cultural and managerial difference may be difficult to consolidate as different authority, reporting and decision-making patterns (Kanter, 1994), therefore leading to possible mistrust and misunderstanding between Golden Bridge and its partners. It has been widely recognized that German managers are prudent and rigid in dealing with regulations and rarely consider the influences of the network relationship, which is fairly distinct from Chinese managers conceptions. Conclusion: In conclusion, according to the PESTEL analysis, there are a number of challenges in China. These challenges can be the unbalanced market condition in china because of local protectionism and insufficient infrastructures, under-developed technology and managerial skill led to the low efficiency of timber industry in China, Natural Forest Protection Program limits the domestic nature timbers supply as well as the increasing labor cost in flooring industry due to Chinas economy prosperous. The complexity of interrelationship of different parties involved in the business environment also cannot be neglected. The PESTEL analysis of German market was further conducted to make the assessment more comprehensive. Later the consultants use five-force model to assess threat of entering the German flooring market. For instance, the competitive rivalry and threat of entry in German flooring market is extremely high. In terms of threat of substitution, it is much more complex. The supplier power and buyer power are both at an intermediate level. However, Porters model is criticized for lacking of corporation with other market players. Thus, a recommendation is made by our consultancy company for Golden Bridge to organize a joint venture and thus with other reliable and competitive companies for instance, the Beamy International. Facts about Germany. (1996). Frankfurt am Main: Società ¤ts Verlag. LeMont Schmidt, P. (2001). Die amerikanische und die deutsche Wirtschaftskultur im Vergleich: Ein Praxisbuch fà ¼r Manager. Gà ¶ttingen: Hainholz Verlag. Guardian (2010) German steel workers demand 6% wage increase http://www.guardian.co.uk/world/2010/sep/14/germany-angela-merkel http://www.roadmap2010.eu/wisd/pdfs/68-81.pdf http://ecotec-energiesparhaus.de/Daten/Holztechnik-Forest-and-wood-industries-in%20Germany%20at-a-glance.pdf http://www.tarkett.com/group/en/company/Tarkett-at-a-glance http://www.homeinstitute.com/types-of-flooring.htm http://news.frbiz.com/parquet_floor_once_again_leading-440481.html http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32004D0275:EN:NOT

Wednesday, September 4, 2019

Types of Security Threats and Protection Against Them

Types of Security Threats and Protection Against Them Introduction While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. A system administrator angered by his diminished role in a thriving defense manufacturing firm whose computer network he alone had developed and managed, centralized the software that supported the company’s manufacturing processes on a single server, and then intimidated a coworker into giving him the only backup tapes for that software. Following the system administrator’s termination for inappropriate and abusive treatment of his coworkers, a logic bomb previously planted by the insider detonated, deleting the only remaining copy of the critical software from the company’s server. The company estimated the cost of damage in excess of $10 million, which led to the layoff of some 80 employees. An application developer, who lost his IT sector job as a result of company downsizing, expressed his displeasure at being laid off just prior to the Christmas holidays by launching a systematic attack on his former employer’s computer network. Three weeks following his termination, the insider used the username and password of one of his former coworkers to gain remote access to the network and modify several of the company’s web pages, changing text and inserting pornographic images. He also sent each of the company’s customers an email message advising that the website had been hacked. Each email message also contained that customer’s usernames and passwords for the website. An investigation was initiated, but it failed to identify the insider as the perpetrator. A month and a half later, he again remotely accessed the network, executed a script to reset all network passwords and changed 4,000 pricing records to reflect bogus information. This former employee ultimately was identified as the perpetrator and prosecuted. He was sentenced to serve five months in prison and two years on supervised probation, and ordered to pay $48,600 restitution to his former employer. A city government employee who was passed over for promotion to finance director retaliated by deleting files from his and a coworker’s computers the day before the new finance director took office. An investigation identified the disgruntled employee as the perpetrator of the incident. City government officials disagreed with the primary police detective on the case as to whether all of the deleted files were recovered. No criminal charges were filed, and, under an agreement with city officials, the employee was allowed to resign. These incidents of sabotage were all committed by â€Å"insiders:† individuals who were, or previously had been, authorized to use the information systems they eventually employed to perpetrate harm. Insiders pose a substantial threat by virtue of their knowledge of, and access to, employer systems and/or databases. Keeney, M., et al (2005) The Nature of Security Threats The greatest threat to computer systems and information comes from humans, through actions that are either malicious or ignorant 3 . Attackers, trying to do harm, exploit vulnerabilities in a system or security policy employing various methods and tools to achieve their aims. Attackers usually have a motive to disrupt normal business operations or to steal information. The above diagram is depicts the types of security threats that exist. The diagram depicts the all threats to the computer systems but main emphasis will be on malicious â€Å"insiders†. The greatest threat of attacks against computer systems are from â€Å"insiders† who know the codes and security measures that are in place 45. With very specific objectives, an insider attack can affect all components of security. As employees with legitimate access to systems, they are familiar with an organization’s computer systems and applications. They are likely to know what actions cause the most damage and how to get away with it undetected. Considered members of the family, they are often above suspicion and the last to be considered when systems malfunction or fail. Disgruntled employees create mischief and sabotage against systems. Organizational downsizing in both public and private sectors has created a group of individuals with significant knowledge and capabilities for malicious activities 6 and revenge. Contract professionals and foreign nationals either brought into the U.S. on work visas to meet labor shortages or from offshore outsourcing projects are also included in this category of knowledgeable insiders. Common Insider Threat Common cases of computer-related employee sabotage include: changing data; deleting data; destroying data or programs with logic bombs; crashing systems; holding data hostage; destroying hardware or facilities; entering data incorrectly, exposing sensitive and embarrassing proprietary data to public view such as the salaries of top executives. Insiders can plant viruses, Trojan horses or worms, browse through file systems or program malicious code with little chance of detection and with almost total impunity. A 1998 FBI Survey 7 investigating computer crime found that of the 520 companies consulted, 64% had reported security breaches for a total quantifiable financial loss of $136 millions. (See chart) The survey also found that the largest number of breaches were by unauthorized insider access and concluded that these figures were very conservative as most companies were unaware of malicious activities or reluctant to report breaches for fear of negative press. The survey reported that the average cost of an attack by an outsider (hacker) at $56,000, while the average insider attack cost a company excess $2.7 million. It found that hidden costs associated with the loss in staff hours, legal liability, loss of proprietary information, decrease in productivity and the potential loss of credibility were impossible to quantify accurately. Employees who have caused damage have used their knowledge and access to information resources for a range of motives, including greed, revenge for perceived grievances, ego gratification, resolution of personal or professional problems, to protect or advance their careers, to challenge their skill, express anger, impress others, or some combination of these concerns. Insider Characteristics The majority of the insiders were former employees. At the time of the incident, 59% of the insiders were former employees or contractors of the affected organizations and 41% were current employees or contractors. The former employees or contractors left their positions for a variety of reasons. These included the insiders being fired (48%), resigning (38%), and being laid off (7%). Most insiders were either previously or currently employed full-time in a technical position within the organization. Most of the insiders (77%) were full-time employees of the affected organizations, either before or during the incidents. Eight percent of the insiders worked part-time, and an additional 8% had been hired as contractors or consultants. Two (4%) of the insiders worked as temporary employees, and one (2%) was hired as a subcontractor. Eighty-six percent of the insiders were employed in technical positions, which included system administrators (38%), programmers (21%), engineers (14%), and IT specialists (14%). Of the insiders not holding technical positions, 10% were employed in a professional position, which included, among others, insiders employed as editors, managers, and auditors. An additional two insiders (4%) worked in service positions, both of whom worked as customer service representatives. Insiders were demographically varied with regard to age, racial and ethnic background, gender, and marital status. The insiders ranged in age from 17 to 60 years (mean age = 32 years)17 and represented a variety of racial and ethnic backgrounds. Ninety-six percent of the insiders were male. Forty-nine percent of the insiders were married at the time of the incident, while 45% were single, having never married, and 4% were divorced. Just under one-third of the insiders had an arrest history. Thirty percent of the insiders had been arrested previously, including arrests for violent offenses (18%), alcohol or drug related offenses (11%), and nonfinancial/ fraud related theft offenses (11%). Organization Characteristics The incidents affected organizations in the following critical infrastructure sectors: Banking and finance (8%) Continuity of government (16%) Defense industrial base (2%) Food (4%) Information and telecommunications (63%) Postal and shipping (2%) Public health (4%) In all, 82% of the affected organizations were in private industry, while 16% were government entities. Sixty-three percent of the organizations engaged in domestic activity only, 2% engaged in international activity only, and 35% engaged in activity both domestically and internationally. What motivate insiders? Internal attackers attempt to break into computer networks for many reasons. The subject has been fruitfully studied and internal attackers are used to be motivated with the following reasons [BSB03]: Challenge Many internal attackers initially attempt to break into networks for the challenge. A challenge combines strategic and tactical thinking, patience, and mental strength. However, internal attackers motivated by the challenge of breaking into networks often do not often think about their actions as criminal. For example, an internal attack can be the challenge to break into the mail server in order to get access to different emails of any employee. Revenge Internal attackers motivated by revenge have often ill feelings toward employees of the same company. These attackers can be particularly dangerous, because they generally focus on a single target, and they generally have patience. In the case of revenge, attackers can also be former employees that feel that they have been wrongfully fired. For example, a former employee may be motivated to launch an attack to the company in order to cause financial losses. Espionage Internal attackers motivated by espionage, steal confidential information for a third party. In general, two types of espionage exists: Industrial espionage Industrial espionage means that a company may pay its own employees in order to break into the networks of its competitors or business partners. The company may also hire someone else to do this. International espionage International espionage means that attackers work for governments and steal confidential information for other governments. Definitions of insider threat 1) The definition of insider threat should encompass two main threat actor categories and five general categories of activities. The first actor category, the â€Å"true insider,† is defined as any entity (person, system, or code) authorized by command and control elements to access network, system, or data. The second actor category, the â€Å"pseudo-insider,† is someone who, by policy, is not authorized the accesses, roles, and/or permissions they currently have but may have gotten them inadvertently or through malicious activities. The activities of both fall into five general categories: Exceeds given network, system or data permissions; Conducts malicious activity against or across the network, system or data; Provided unapproved access to the network, system or data; Circumvents security controls or exploits security weaknesses to exceed authorized permitted activity or disguise identify; or Non-maliciously or unintentionally damages resources (network, system or data) by destruction, corruption, denial of access, or disclosure. (Presented at the University of Louisville Cyber Securitys Day, October 2006) 2) Insiders — employees, contractors, consultants, and vendors — pose as great a threat to an organization’s security posture as outsiders, including hackers. Few organizations have implemented the policies, procedures, tools, or strategies to effectively address their insider threats. An insider threat assessment is a recommended first step for many organizations, followed by policy review, and employee awareness training. (Insider Threat Management Presented by infoLock Technologies) 3) Employees are an organization’s most important asset. Unfortunately, they also present the greatest security risks. Working and communicating remotely, storing sensitive data on portable devices such as laptops, PDAs, thumb drives, and even iPods employees have extended the security perimeter beyond safe limits. While convenient access to data is required for operational efficiency, the actions of trusted insiders not just employees, but consultants, contactors, vendors, and partners must be actively managed, audited, and monitored in order to protect sensitive data. (Presented by infoLock Technologies) 4) The diversity of cyber threat has grown over time from network-level attacks and password cracking to include newer classes such as insider attacks, email worms and social engineering, which are currently recognized as serious security problems. However, attack modeling and threat analysis tools have not evolved at the same rate. Known formal models such as attack graphs perform action-centric vulnerability modeling and analysis. All possible atomic user actions are represented as states, and sequences which lead to the violation of a specie safety property are extracted to indicate possible exploits. (Ramkumar Chinchani, Anusha Iyer, Hung Ngo, Shambhu Upadhyaya) 5) The Insider Threat Study, conducted by the U.S. Secret Service and Carnegie Mellon University’s Software Engineering Institute CERT Program, analyzed insider cyber crimes across U.S. critical infrastructure sectors. The study indicates that management decisions related to organizational and employee performance sometimes yield unintended consequences magnifying risk of insider attack. Lack of tools for understanding insider threat, analyzing risk mitigation alternatives, and communicating results exacerbates the problem. (Dawn M. Cappelli, Akash G. Desai) 6) The insider threat or insider problem is cited as the most serious security problem in many studies. It is also considered the most difficult problem to deal with, because an insider has information and capabilities not known to other, external attackers. But the studies rarely define what the insider threat is, or define it nebulously. The difficulty in handling the insider threat is reasonable under those circumstances; if one cannot define a problem precisely, how can one approach a solution, let alone know when the problem is solved? (Matt Bishop 2005) Five common insider threat Exploiting information via remote access software A considerable amount of insider abuse is performed offsite via remote access software such as Terminal Services, Citrix and GoToMyPC. Simply put, users are less likely to be caught stealing sensitive information when they can it do offsite. Also, inadequately protected remote computers may turn up in the hands of a third-party if the computer is left unattended, lost or stolen. 2.) Sending out information via e-mail and instant messaging Sensitive information can simply be included in or attached to an e-mail or IM. Although this is a serious threat, its also one of the easiest to eliminate. 3.) Sharing sensitive files on P2P networks Whether or not you allow peer-to-peer file sharing software such as Kazaa or IM on your network, odds are its there and waiting to be abused. The inanimate software in and of itself is not the problem – its how its used that causes trouble. All it takes is a simple misconfiguration to serve up your networks local and network drives to the world. 4.) Careless use of wireless networks Perhaps the most unintentional insider threat is that of insecure wireless network usage. Whether its at a coffee shop, airport or hotel, unsecured airwaves can easily put sensitive information in jeopardy. All it takes is a peek into e-mail communications or file transfers for valuable data to be stolen. Wi-Fi networks are most susceptible to these attacks, but dont overlook Bluetooth on smartphones and PDAs. Also, if you have WLANs inside your organization, employees could use it to exploit the network after hours. 5.) Posting information to discussion boards and blogs Quite often users post support requests, blogs or other work-related messages on the Internet. Whether intentional or not, this can include sensitive information and file attachments that put your organization at risk. Views of different authors about insider threat 1) Although insiders in this report tended to be former technical employees, there is no demographic â€Å"profile† of a malicious insider. Ages of perpetrators ranged from late teens to retirement. Both men and women were malicious insiders. Their positions included programmers, graphic artists, system and network administrators, managers, and executives. They were currently employed and recently terminated employees, contractors, and temporary employees. As such, security awareness training needs to encourage employees to identify malicious insiders by behavior, not by stereotypical characteristics. For example, behaviors that should be a source of concern include making threats against the organization, bragging about the damage one could do to the organization, or discussing plans to work against the organization. Also of concern are attempts to gain other employees’ passwords and to fraudulently obtain access through trickery or exploitation of a trusted relationsh ip. Insiders can be stopped, but stopping them is a complex problem. Insider attacks can only be prevented through a layered defense strategy consisting of policies, procedures, and technical controls. Therefore, management must pay close attention to many aspects of its organization, including its business policies and procedures, organizational culture, and technical environment. Organizations must look beyond information technology to the organization’s overall business processes and the interplay between those processes and the technologies used. (Michelle Keeney, J.D., Ph.D. atal 2005) 2) While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. (Nam Nguyen and Peter Reiher, Geoffrey H. Kuenning) 3) Geographically distributed information systems achieve high availability that is crucial to their usefulness by replicating their state. Providing instant access at time of need regardless of current network connectivity requires the state to be replicated in every geographical site so that it is locally available. As network environments become increasingly hostile, we have to assume that part of the distributed information system will be compromised at some point. The problem of maintaining a replicated state in such a system is magnified when insider (or Byzantine) attacks are taken into account. (Yair Amir Cristina Nita-Rotaru) 4) In 2006, over 60% of information security breaches were attributable to insider behavior, yet more than 80% of corporate IT security budgets were spent on securing perimeter defenses against outside attack. Protecting against insider threats means managing policy, process, technology, and most importantly, people. Protecting against insider threats means managing policy, process, technology, and most importantly, people.The Insider Threat Assessment security awareness training, infrastructure reconfiguration, or third party solutions, you can take comfort in knowing that you have made the right choice to improve your security posture, and you will achieve your expected Return on Security Investment. (Presented by infoLock Technologies) 5) The threat of attack from insiders is real and substantial. The 2004 ECrime Watch Survey TM conducted by the United States Secret Service, CERT  ® Coordination Center (CERT/CC), and CSO Magazine, 1 found that in cases where respondents could identify the perpetrator of an electronic crime, 29 percent were committed by insiders. The impact from insider attacks can be devastating. One complex case of financial fraud committed by an insider in a financial institution resulted in losses of over $600 million. 2 Another case involving a logic bomb written by a technical employee working for a defense contractor resulted in $10 million in losses and the layoff of 80 employees. (Dawn Cappelli, Andrew Moore, Timothy Shimeall,2005) 6) Insiders, by virtue of legitimate access to their organizations’ information, systems, and networks, pose a significant risk to employers. Employees experiencing financial problems have found it easy to use the systems they use at work everyday to commit fraud. Other employees, motivated by financial problems, greed, or the wish to impress a new employer, have stolen confidential data, proprietary information, or intellectual property from their employer. Lastly, technical employees, possibly the most dangerous because of their intimate knowledge of an organization’s vulnerabilities, have used their technical ability to sabotage their employer’s system or network in revenge for some negative work-related event. (Dawn M. Cappelli, Akash G. Desai ,at al 2004) 7) The insider problem is considered the most difficult and critical problem in computer security. But studies that survey the seriousness of the problem, and research that analyzes the problem, rarely define the problem precisely. Implicit definitions vary in meaning. Different definitions imply different countermeasures, as well as different assumptions. (Matt Bishop 2005) Solution: User monitoring Insiders have two things that external attackers don’t: privileged access and trust. This allows them to bypass preventative measures, access mission-critical assets, and conduct malicious acts all while flying under the radar unless a strong incident detection solution is in place. A number of variables motivate insiders, but the end result is that they can more easily perpetrate their crimes than an outsider who has limited access. Insiders can directly damage your business resulting in lost revenue, lost customers, reduced shareholder faith, a tarnished reputation, regulatory fines and legal fees. With such an expansive threat, organizations need an automated solution to help detect and analyze Malicious Insider Activity These are some points which could be helpful in monitoring and minimizing the insider threats: Detecting insider activity starts with an expanded log and event collection. Firewalls, routers and intrusion detection systems are important, but they are not enough. Organizations need to look deeper to include mission critical applications such as email applications, databases, operating systems, mainframes, access control solutions, physical security systems as well as identity and content management products. Correlation: identifying known types of suspicious and malicious behavior Anomaly detection: recognizing deviations from norms and baselines. Pattern discovery: uncovering seemingly unrelated events that show a pattern of suspicious activity From case management, event annotation and escalation to reporting, auditing and access to insider-relevant information, the technical solution must be in line with the organization’s procedures. This will ensure that insiders are addressed consistently, efficiently and effectively regardless of who they are. Identify suspicious user activity patterns and identify anomalies. Visually track and create business-level reports on user’s activity. Automatically escalate the threat levels of suspicious and malicious individuals. Respond according to your specific and unique corporate governing guidelines. Early detection of insider activity based on early warning indicators of suspicious behavior, such as: Stale or terminated accounts Excessive file printing, unusual printing times and keywords printed Traffic to suspicious destinations Unauthorized peripheral device access Bypassing security controls Attempts to alter or delete system logs Installation of malicious software The Insider Threat Study? The global acceptance, business adoption and growth of the Internet, and of Internetworking technologies in general, in response to customer requests for online access to business information systems, has ushered in an extraordinary expansion of electronic business transactions. In moving from internal (closed) business systems to open systems, the risk of malicious attacks and fraudulent activity has increased enormously, thereby requiring high levels of information security. Prior to the requirement for online, open access, the information security budget of a typical company was less then their tea and coffee expenses. Securing cyberspace has become a national priority. In The National Strategy to Secure Cyberspace, the President’s Critical Infrastructure Protection Board identified several critical infrastructure sectors10: banking and finance information and telecommunications transportation postal and shipping emergency services continuity of government public health Universities chemical industry, textile industry and hazardous materials agriculture defense industrial base The cases examined in the Insider Threat Study are incidents perpetrated by insiders (current or former employees or contractors) who intentionally exceeded or misused an authorized level of network, system, or data access in a manner that affected the security of the organizations’ data, systems, or daily business operations. Incidents included any compromise, manipulation of, unauthorized access to, exceeding authorized access to, tampering with, or disabling of any information system, network, or data. The cases examined also included any in which there was an unauthorized or illegal attempt to view, disclose, retrieve, delete, change, or add information. A completely secure, zero risk system is one which has zero functionality. Latest technology high-performance automated systems bring with them new risks in the shape of new attacks, new viruses and new software bugs, etc. IT Security, therefore, is an ongoing process. Proper risk management keeps the IT Security plans, policies and procedures up to date as per new requirements and changes in the computing environment. To implement controls to counter risks requires policies, and policy can only be implemented successfully if the top management is committed. And policy’s effective implementation is not possible without the training and awareness of staff. The State Bank of Pakistan recognizes that financial industry is built around the sanctity of the financial transactions. Owing to the critical role of financial institutions for a country and the extreme sensitivity of their information assets, the seriousness of IT Security and the ever-increasing threats it faces in today’s open world cannot be overstated. As more and more of our Banking Operations and products services become technology driven and dependent, consequently our reliance on these technology assets increases, and so does the need to protect and safeguard these resources to ensure smooth functioning of the financial industry. Here are different area in which we can work and check insider threat, but I chose textile industry as in textile industry there is less awareness of the insider threat. If an insider attack in an industry then industrialist try to cover up this news as these types of news about an industry can damage the reputation of the industry. Chapter 2 Review of Literature S, Axelsson. ,(2000) Anonymous 2001 Continuity of operations and correct functioning of information systems is important to most businesses. Threats to computerised information and process are threats to business quality and effectiveness. The objective of IT security is to put measures in place which eliminate or reduce significant threats to an acceptable level. Security and risk management are tightly coupled with quality management. Security measures should be implemented based on risk analysis and in harmony with Quality structures, processes and checklists. What needs to be protected, against whom and how? Security is the protection of information, systems and services against disasters, mistakes and manipulation so that the likelihood and impact of security incidents is minimised. IT security is comprised of: Confidentiality: Sensitive business objects (information processes) are disclosed only to authorised persons. ==> Controls are required to restrict access to objects. Integrity: The business need to control modification to objects (information and processes). ==> Controls are required to ensure objects are accurate and complete. Availability: The need to have business objects (information and services) available when needed. ==> Controls are required to ensure reliability of services. Legal Compliance: Information/data that is collected, processed, used, passed on or destroyed must be handled in line with current legislation of the relevant countries. A threat is a danger which could affect the security (confidentiality, integrity, availability) of assets, leading to a potential loss or damage. Stoneburner et al (2002) In this paper the author described a the risks which are Types of Security Threats and Protection Against Them Types of Security Threats and Protection Against Them Introduction While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. A system administrator angered by his diminished role in a thriving defense manufacturing firm whose computer network he alone had developed and managed, centralized the software that supported the company’s manufacturing processes on a single server, and then intimidated a coworker into giving him the only backup tapes for that software. Following the system administrator’s termination for inappropriate and abusive treatment of his coworkers, a logic bomb previously planted by the insider detonated, deleting the only remaining copy of the critical software from the company’s server. The company estimated the cost of damage in excess of $10 million, which led to the layoff of some 80 employees. An application developer, who lost his IT sector job as a result of company downsizing, expressed his displeasure at being laid off just prior to the Christmas holidays by launching a systematic attack on his former employer’s computer network. Three weeks following his termination, the insider used the username and password of one of his former coworkers to gain remote access to the network and modify several of the company’s web pages, changing text and inserting pornographic images. He also sent each of the company’s customers an email message advising that the website had been hacked. Each email message also contained that customer’s usernames and passwords for the website. An investigation was initiated, but it failed to identify the insider as the perpetrator. A month and a half later, he again remotely accessed the network, executed a script to reset all network passwords and changed 4,000 pricing records to reflect bogus information. This former employee ultimately was identified as the perpetrator and prosecuted. He was sentenced to serve five months in prison and two years on supervised probation, and ordered to pay $48,600 restitution to his former employer. A city government employee who was passed over for promotion to finance director retaliated by deleting files from his and a coworker’s computers the day before the new finance director took office. An investigation identified the disgruntled employee as the perpetrator of the incident. City government officials disagreed with the primary police detective on the case as to whether all of the deleted files were recovered. No criminal charges were filed, and, under an agreement with city officials, the employee was allowed to resign. These incidents of sabotage were all committed by â€Å"insiders:† individuals who were, or previously had been, authorized to use the information systems they eventually employed to perpetrate harm. Insiders pose a substantial threat by virtue of their knowledge of, and access to, employer systems and/or databases. Keeney, M., et al (2005) The Nature of Security Threats The greatest threat to computer systems and information comes from humans, through actions that are either malicious or ignorant 3 . Attackers, trying to do harm, exploit vulnerabilities in a system or security policy employing various methods and tools to achieve their aims. Attackers usually have a motive to disrupt normal business operations or to steal information. The above diagram is depicts the types of security threats that exist. The diagram depicts the all threats to the computer systems but main emphasis will be on malicious â€Å"insiders†. The greatest threat of attacks against computer systems are from â€Å"insiders† who know the codes and security measures that are in place 45. With very specific objectives, an insider attack can affect all components of security. As employees with legitimate access to systems, they are familiar with an organization’s computer systems and applications. They are likely to know what actions cause the most damage and how to get away with it undetected. Considered members of the family, they are often above suspicion and the last to be considered when systems malfunction or fail. Disgruntled employees create mischief and sabotage against systems. Organizational downsizing in both public and private sectors has created a group of individuals with significant knowledge and capabilities for malicious activities 6 and revenge. Contract professionals and foreign nationals either brought into the U.S. on work visas to meet labor shortages or from offshore outsourcing projects are also included in this category of knowledgeable insiders. Common Insider Threat Common cases of computer-related employee sabotage include: changing data; deleting data; destroying data or programs with logic bombs; crashing systems; holding data hostage; destroying hardware or facilities; entering data incorrectly, exposing sensitive and embarrassing proprietary data to public view such as the salaries of top executives. Insiders can plant viruses, Trojan horses or worms, browse through file systems or program malicious code with little chance of detection and with almost total impunity. A 1998 FBI Survey 7 investigating computer crime found that of the 520 companies consulted, 64% had reported security breaches for a total quantifiable financial loss of $136 millions. (See chart) The survey also found that the largest number of breaches were by unauthorized insider access and concluded that these figures were very conservative as most companies were unaware of malicious activities or reluctant to report breaches for fear of negative press. The survey reported that the average cost of an attack by an outsider (hacker) at $56,000, while the average insider attack cost a company excess $2.7 million. It found that hidden costs associated with the loss in staff hours, legal liability, loss of proprietary information, decrease in productivity and the potential loss of credibility were impossible to quantify accurately. Employees who have caused damage have used their knowledge and access to information resources for a range of motives, including greed, revenge for perceived grievances, ego gratification, resolution of personal or professional problems, to protect or advance their careers, to challenge their skill, express anger, impress others, or some combination of these concerns. Insider Characteristics The majority of the insiders were former employees. At the time of the incident, 59% of the insiders were former employees or contractors of the affected organizations and 41% were current employees or contractors. The former employees or contractors left their positions for a variety of reasons. These included the insiders being fired (48%), resigning (38%), and being laid off (7%). Most insiders were either previously or currently employed full-time in a technical position within the organization. Most of the insiders (77%) were full-time employees of the affected organizations, either before or during the incidents. Eight percent of the insiders worked part-time, and an additional 8% had been hired as contractors or consultants. Two (4%) of the insiders worked as temporary employees, and one (2%) was hired as a subcontractor. Eighty-six percent of the insiders were employed in technical positions, which included system administrators (38%), programmers (21%), engineers (14%), and IT specialists (14%). Of the insiders not holding technical positions, 10% were employed in a professional position, which included, among others, insiders employed as editors, managers, and auditors. An additional two insiders (4%) worked in service positions, both of whom worked as customer service representatives. Insiders were demographically varied with regard to age, racial and ethnic background, gender, and marital status. The insiders ranged in age from 17 to 60 years (mean age = 32 years)17 and represented a variety of racial and ethnic backgrounds. Ninety-six percent of the insiders were male. Forty-nine percent of the insiders were married at the time of the incident, while 45% were single, having never married, and 4% were divorced. Just under one-third of the insiders had an arrest history. Thirty percent of the insiders had been arrested previously, including arrests for violent offenses (18%), alcohol or drug related offenses (11%), and nonfinancial/ fraud related theft offenses (11%). Organization Characteristics The incidents affected organizations in the following critical infrastructure sectors: Banking and finance (8%) Continuity of government (16%) Defense industrial base (2%) Food (4%) Information and telecommunications (63%) Postal and shipping (2%) Public health (4%) In all, 82% of the affected organizations were in private industry, while 16% were government entities. Sixty-three percent of the organizations engaged in domestic activity only, 2% engaged in international activity only, and 35% engaged in activity both domestically and internationally. What motivate insiders? Internal attackers attempt to break into computer networks for many reasons. The subject has been fruitfully studied and internal attackers are used to be motivated with the following reasons [BSB03]: Challenge Many internal attackers initially attempt to break into networks for the challenge. A challenge combines strategic and tactical thinking, patience, and mental strength. However, internal attackers motivated by the challenge of breaking into networks often do not often think about their actions as criminal. For example, an internal attack can be the challenge to break into the mail server in order to get access to different emails of any employee. Revenge Internal attackers motivated by revenge have often ill feelings toward employees of the same company. These attackers can be particularly dangerous, because they generally focus on a single target, and they generally have patience. In the case of revenge, attackers can also be former employees that feel that they have been wrongfully fired. For example, a former employee may be motivated to launch an attack to the company in order to cause financial losses. Espionage Internal attackers motivated by espionage, steal confidential information for a third party. In general, two types of espionage exists: Industrial espionage Industrial espionage means that a company may pay its own employees in order to break into the networks of its competitors or business partners. The company may also hire someone else to do this. International espionage International espionage means that attackers work for governments and steal confidential information for other governments. Definitions of insider threat 1) The definition of insider threat should encompass two main threat actor categories and five general categories of activities. The first actor category, the â€Å"true insider,† is defined as any entity (person, system, or code) authorized by command and control elements to access network, system, or data. The second actor category, the â€Å"pseudo-insider,† is someone who, by policy, is not authorized the accesses, roles, and/or permissions they currently have but may have gotten them inadvertently or through malicious activities. The activities of both fall into five general categories: Exceeds given network, system or data permissions; Conducts malicious activity against or across the network, system or data; Provided unapproved access to the network, system or data; Circumvents security controls or exploits security weaknesses to exceed authorized permitted activity or disguise identify; or Non-maliciously or unintentionally damages resources (network, system or data) by destruction, corruption, denial of access, or disclosure. (Presented at the University of Louisville Cyber Securitys Day, October 2006) 2) Insiders — employees, contractors, consultants, and vendors — pose as great a threat to an organization’s security posture as outsiders, including hackers. Few organizations have implemented the policies, procedures, tools, or strategies to effectively address their insider threats. An insider threat assessment is a recommended first step for many organizations, followed by policy review, and employee awareness training. (Insider Threat Management Presented by infoLock Technologies) 3) Employees are an organization’s most important asset. Unfortunately, they also present the greatest security risks. Working and communicating remotely, storing sensitive data on portable devices such as laptops, PDAs, thumb drives, and even iPods employees have extended the security perimeter beyond safe limits. While convenient access to data is required for operational efficiency, the actions of trusted insiders not just employees, but consultants, contactors, vendors, and partners must be actively managed, audited, and monitored in order to protect sensitive data. (Presented by infoLock Technologies) 4) The diversity of cyber threat has grown over time from network-level attacks and password cracking to include newer classes such as insider attacks, email worms and social engineering, which are currently recognized as serious security problems. However, attack modeling and threat analysis tools have not evolved at the same rate. Known formal models such as attack graphs perform action-centric vulnerability modeling and analysis. All possible atomic user actions are represented as states, and sequences which lead to the violation of a specie safety property are extracted to indicate possible exploits. (Ramkumar Chinchani, Anusha Iyer, Hung Ngo, Shambhu Upadhyaya) 5) The Insider Threat Study, conducted by the U.S. Secret Service and Carnegie Mellon University’s Software Engineering Institute CERT Program, analyzed insider cyber crimes across U.S. critical infrastructure sectors. The study indicates that management decisions related to organizational and employee performance sometimes yield unintended consequences magnifying risk of insider attack. Lack of tools for understanding insider threat, analyzing risk mitigation alternatives, and communicating results exacerbates the problem. (Dawn M. Cappelli, Akash G. Desai) 6) The insider threat or insider problem is cited as the most serious security problem in many studies. It is also considered the most difficult problem to deal with, because an insider has information and capabilities not known to other, external attackers. But the studies rarely define what the insider threat is, or define it nebulously. The difficulty in handling the insider threat is reasonable under those circumstances; if one cannot define a problem precisely, how can one approach a solution, let alone know when the problem is solved? (Matt Bishop 2005) Five common insider threat Exploiting information via remote access software A considerable amount of insider abuse is performed offsite via remote access software such as Terminal Services, Citrix and GoToMyPC. Simply put, users are less likely to be caught stealing sensitive information when they can it do offsite. Also, inadequately protected remote computers may turn up in the hands of a third-party if the computer is left unattended, lost or stolen. 2.) Sending out information via e-mail and instant messaging Sensitive information can simply be included in or attached to an e-mail or IM. Although this is a serious threat, its also one of the easiest to eliminate. 3.) Sharing sensitive files on P2P networks Whether or not you allow peer-to-peer file sharing software such as Kazaa or IM on your network, odds are its there and waiting to be abused. The inanimate software in and of itself is not the problem – its how its used that causes trouble. All it takes is a simple misconfiguration to serve up your networks local and network drives to the world. 4.) Careless use of wireless networks Perhaps the most unintentional insider threat is that of insecure wireless network usage. Whether its at a coffee shop, airport or hotel, unsecured airwaves can easily put sensitive information in jeopardy. All it takes is a peek into e-mail communications or file transfers for valuable data to be stolen. Wi-Fi networks are most susceptible to these attacks, but dont overlook Bluetooth on smartphones and PDAs. Also, if you have WLANs inside your organization, employees could use it to exploit the network after hours. 5.) Posting information to discussion boards and blogs Quite often users post support requests, blogs or other work-related messages on the Internet. Whether intentional or not, this can include sensitive information and file attachments that put your organization at risk. Views of different authors about insider threat 1) Although insiders in this report tended to be former technical employees, there is no demographic â€Å"profile† of a malicious insider. Ages of perpetrators ranged from late teens to retirement. Both men and women were malicious insiders. Their positions included programmers, graphic artists, system and network administrators, managers, and executives. They were currently employed and recently terminated employees, contractors, and temporary employees. As such, security awareness training needs to encourage employees to identify malicious insiders by behavior, not by stereotypical characteristics. For example, behaviors that should be a source of concern include making threats against the organization, bragging about the damage one could do to the organization, or discussing plans to work against the organization. Also of concern are attempts to gain other employees’ passwords and to fraudulently obtain access through trickery or exploitation of a trusted relationsh ip. Insiders can be stopped, but stopping them is a complex problem. Insider attacks can only be prevented through a layered defense strategy consisting of policies, procedures, and technical controls. Therefore, management must pay close attention to many aspects of its organization, including its business policies and procedures, organizational culture, and technical environment. Organizations must look beyond information technology to the organization’s overall business processes and the interplay between those processes and the technologies used. (Michelle Keeney, J.D., Ph.D. atal 2005) 2) While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. (Nam Nguyen and Peter Reiher, Geoffrey H. Kuenning) 3) Geographically distributed information systems achieve high availability that is crucial to their usefulness by replicating their state. Providing instant access at time of need regardless of current network connectivity requires the state to be replicated in every geographical site so that it is locally available. As network environments become increasingly hostile, we have to assume that part of the distributed information system will be compromised at some point. The problem of maintaining a replicated state in such a system is magnified when insider (or Byzantine) attacks are taken into account. (Yair Amir Cristina Nita-Rotaru) 4) In 2006, over 60% of information security breaches were attributable to insider behavior, yet more than 80% of corporate IT security budgets were spent on securing perimeter defenses against outside attack. Protecting against insider threats means managing policy, process, technology, and most importantly, people. Protecting against insider threats means managing policy, process, technology, and most importantly, people.The Insider Threat Assessment security awareness training, infrastructure reconfiguration, or third party solutions, you can take comfort in knowing that you have made the right choice to improve your security posture, and you will achieve your expected Return on Security Investment. (Presented by infoLock Technologies) 5) The threat of attack from insiders is real and substantial. The 2004 ECrime Watch Survey TM conducted by the United States Secret Service, CERT  ® Coordination Center (CERT/CC), and CSO Magazine, 1 found that in cases where respondents could identify the perpetrator of an electronic crime, 29 percent were committed by insiders. The impact from insider attacks can be devastating. One complex case of financial fraud committed by an insider in a financial institution resulted in losses of over $600 million. 2 Another case involving a logic bomb written by a technical employee working for a defense contractor resulted in $10 million in losses and the layoff of 80 employees. (Dawn Cappelli, Andrew Moore, Timothy Shimeall,2005) 6) Insiders, by virtue of legitimate access to their organizations’ information, systems, and networks, pose a significant risk to employers. Employees experiencing financial problems have found it easy to use the systems they use at work everyday to commit fraud. Other employees, motivated by financial problems, greed, or the wish to impress a new employer, have stolen confidential data, proprietary information, or intellectual property from their employer. Lastly, technical employees, possibly the most dangerous because of their intimate knowledge of an organization’s vulnerabilities, have used their technical ability to sabotage their employer’s system or network in revenge for some negative work-related event. (Dawn M. Cappelli, Akash G. Desai ,at al 2004) 7) The insider problem is considered the most difficult and critical problem in computer security. But studies that survey the seriousness of the problem, and research that analyzes the problem, rarely define the problem precisely. Implicit definitions vary in meaning. Different definitions imply different countermeasures, as well as different assumptions. (Matt Bishop 2005) Solution: User monitoring Insiders have two things that external attackers don’t: privileged access and trust. This allows them to bypass preventative measures, access mission-critical assets, and conduct malicious acts all while flying under the radar unless a strong incident detection solution is in place. A number of variables motivate insiders, but the end result is that they can more easily perpetrate their crimes than an outsider who has limited access. Insiders can directly damage your business resulting in lost revenue, lost customers, reduced shareholder faith, a tarnished reputation, regulatory fines and legal fees. With such an expansive threat, organizations need an automated solution to help detect and analyze Malicious Insider Activity These are some points which could be helpful in monitoring and minimizing the insider threats: Detecting insider activity starts with an expanded log and event collection. Firewalls, routers and intrusion detection systems are important, but they are not enough. Organizations need to look deeper to include mission critical applications such as email applications, databases, operating systems, mainframes, access control solutions, physical security systems as well as identity and content management products. Correlation: identifying known types of suspicious and malicious behavior Anomaly detection: recognizing deviations from norms and baselines. Pattern discovery: uncovering seemingly unrelated events that show a pattern of suspicious activity From case management, event annotation and escalation to reporting, auditing and access to insider-relevant information, the technical solution must be in line with the organization’s procedures. This will ensure that insiders are addressed consistently, efficiently and effectively regardless of who they are. Identify suspicious user activity patterns and identify anomalies. Visually track and create business-level reports on user’s activity. Automatically escalate the threat levels of suspicious and malicious individuals. Respond according to your specific and unique corporate governing guidelines. Early detection of insider activity based on early warning indicators of suspicious behavior, such as: Stale or terminated accounts Excessive file printing, unusual printing times and keywords printed Traffic to suspicious destinations Unauthorized peripheral device access Bypassing security controls Attempts to alter or delete system logs Installation of malicious software The Insider Threat Study? The global acceptance, business adoption and growth of the Internet, and of Internetworking technologies in general, in response to customer requests for online access to business information systems, has ushered in an extraordinary expansion of electronic business transactions. In moving from internal (closed) business systems to open systems, the risk of malicious attacks and fraudulent activity has increased enormously, thereby requiring high levels of information security. Prior to the requirement for online, open access, the information security budget of a typical company was less then their tea and coffee expenses. Securing cyberspace has become a national priority. In The National Strategy to Secure Cyberspace, the President’s Critical Infrastructure Protection Board identified several critical infrastructure sectors10: banking and finance information and telecommunications transportation postal and shipping emergency services continuity of government public health Universities chemical industry, textile industry and hazardous materials agriculture defense industrial base The cases examined in the Insider Threat Study are incidents perpetrated by insiders (current or former employees or contractors) who intentionally exceeded or misused an authorized level of network, system, or data access in a manner that affected the security of the organizations’ data, systems, or daily business operations. Incidents included any compromise, manipulation of, unauthorized access to, exceeding authorized access to, tampering with, or disabling of any information system, network, or data. The cases examined also included any in which there was an unauthorized or illegal attempt to view, disclose, retrieve, delete, change, or add information. A completely secure, zero risk system is one which has zero functionality. Latest technology high-performance automated systems bring with them new risks in the shape of new attacks, new viruses and new software bugs, etc. IT Security, therefore, is an ongoing process. Proper risk management keeps the IT Security plans, policies and procedures up to date as per new requirements and changes in the computing environment. To implement controls to counter risks requires policies, and policy can only be implemented successfully if the top management is committed. And policy’s effective implementation is not possible without the training and awareness of staff. The State Bank of Pakistan recognizes that financial industry is built around the sanctity of the financial transactions. Owing to the critical role of financial institutions for a country and the extreme sensitivity of their information assets, the seriousness of IT Security and the ever-increasing threats it faces in today’s open world cannot be overstated. As more and more of our Banking Operations and products services become technology driven and dependent, consequently our reliance on these technology assets increases, and so does the need to protect and safeguard these resources to ensure smooth functioning of the financial industry. Here are different area in which we can work and check insider threat, but I chose textile industry as in textile industry there is less awareness of the insider threat. If an insider attack in an industry then industrialist try to cover up this news as these types of news about an industry can damage the reputation of the industry. Chapter 2 Review of Literature S, Axelsson. ,(2000) Anonymous 2001 Continuity of operations and correct functioning of information systems is important to most businesses. Threats to computerised information and process are threats to business quality and effectiveness. The objective of IT security is to put measures in place which eliminate or reduce significant threats to an acceptable level. Security and risk management are tightly coupled with quality management. Security measures should be implemented based on risk analysis and in harmony with Quality structures, processes and checklists. What needs to be protected, against whom and how? Security is the protection of information, systems and services against disasters, mistakes and manipulation so that the likelihood and impact of security incidents is minimised. IT security is comprised of: Confidentiality: Sensitive business objects (information processes) are disclosed only to authorised persons. ==> Controls are required to restrict access to objects. Integrity: The business need to control modification to objects (information and processes). ==> Controls are required to ensure objects are accurate and complete. Availability: The need to have business objects (information and services) available when needed. ==> Controls are required to ensure reliability of services. Legal Compliance: Information/data that is collected, processed, used, passed on or destroyed must be handled in line with current legislation of the relevant countries. A threat is a danger which could affect the security (confidentiality, integrity, availability) of assets, leading to a potential loss or damage. Stoneburner et al (2002) In this paper the author described a the risks which are