<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.solidcore.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.solidcore.com/public/?>

<MySmartChannels Public="true" UserID="183000" dT="98" t0="1231330387218">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>209449</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] ITIL">183011</OwnerID>
        <CreatedByID ObjectClass="User" Title="tthompson">204728</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="tthompson">204728</ModifiedByID>
        <CreateTime Title="2008-07-21 14:29:13 EDT">1216664953805</CreateTime>
        <ModifyTime Title="2008-07-21 16:48:55 EDT">1216673335327</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>Insider IT Sabotage - Super Villain of the Digital World?</Name>
        <Summary>San Francisco network sabotage leaves administrators feeling helpless</Summary>
        <Description>&lt;p&gt;&lt;img style="WIDTH: 69px; HEIGHT: 97px" height="97" alt="Hancock mirrors IT sabotage as super villain" hspace="0" src="http://larryfire.files.wordpress.com/2008/04/hancock1.jpg" width="69" align="baseline" border="0" /&gt;It's still &amp;quot;dark&amp;quot; within the city of &lt;a title="ChannelWeb story on San Francisco network lock-out" href="http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;San Francisco's network&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and IT organization after it was determined one of its own&amp;nbsp;network administrators went rogue and changed passwords and allegedly enabled lock-out code preventing any others from accessing the key components. He is still&amp;nbsp;holding the master password for ransom.&lt;/p&gt;&lt;p&gt;According to Insider &lt;a href="www.cert.org/insider_threat"&gt;&lt;strong&gt;&lt;u&gt;Threat Research&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; from CERT there most likely would have been pre-cursory warning signs:&lt;/p&gt;&lt;p&gt;Summary of Observations made within a study conducted by CERT, US Secret Service and the National Threat Assessment Center&lt;/p&gt;&lt;p&gt;- 90% of Insiders were granted system administrator or privileged system access when hired by the organization&lt;/p&gt;&lt;p&gt;- 57% of Insiders were perceived as being disgruntled due to unmet expectations&lt;/p&gt;&lt;p&gt;- 92% of Insiders attacked following&amp;nbsp;a negative work-related situation such as termination, dispute with employer, demotion or transfer&lt;/p&gt;&lt;p&gt;- 87% of Insiders performed technical precursors prior to the attack that were undetected by the organization&lt;/p&gt;&lt;p&gt;- 75% of Insiders created access paths unknown to the organization, 57% did not have authorized system access at the time of the attack&lt;/p&gt;&lt;p&gt;- 93% of Insiders exploited insufficient access controls&lt;/p&gt;&lt;p&gt;This should be chapter one in the &amp;quot;Worst Case Scenario&amp;quot; book for CIOs and corporate boards.&lt;/p&gt;&lt;p&gt;Ensure that controls are in place to allow IT administrators (role) to perform their duties (responsibilities) within their job function and scope (segmentation). However monitor, track and alert on all password changes to ensure that the keys to the digital foundation of your organization are not enabling IT Sabotage and or malicious hi-jinks.&lt;/p&gt;&lt;p&gt;This type of drama is unfolding like a comic book, similar to the Marvel comic character Rogue, who at times is good, at times is evil but shares one trait with today's Digital Super Villain&amp;nbsp;- the ability to absorb the powers of others. This could even be exemplifed by the modern day boxoffice thriller &lt;a title="Sony pictures Hancock official site" href="http://www.sonypictures.com/movies/hancock/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Hancock&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Bottom line: Don't let your controls only be policies on paper.&amp;nbsp;Make sure you have the power of enforcement!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Kim Singletary&lt;br /&gt;&lt;/b&gt;Director of Embedded Solutions&lt;br /&gt;&lt;a href="mailto:ksingletary@solidcore.com"&gt;ksingletary@solidcore.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Rajesh Rajamani&lt;br /&gt;&lt;/b&gt;Product Manager&lt;br /&gt;&lt;a href="mailto:raj@solidcore.com"&gt;raj@solidcore.com&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>change control</Keyword>

                 <Keyword>Hancock</Keyword>

                 <Keyword>network hijack</Keyword>

                 <Keyword>San Francisco hack</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>San Francisco Network Hijack</Title>

                  <Synopsis>ChannelWeb news story on the San Francisco network lock-out</Synopsis>

                  <URL>http://www.crn.com/security/209101383?cid=ChannelWebBreakingNews</URL>

        </Link>

                 <Link>
                  <Title>CERT Research on Insider Threat</Title>

                  <Synopsis>Insider threat research from CERT</Synopsis>

                  <URL>http://www.cert.org/insider_threat/</URL>

        </Link>

                 <Link>
                  <Title>Hancock</Title>

                  <Synopsis>Sony pictures Hancock page</Synopsis>

                  <URL>http://www.sonypictures.com/movies/hancock/</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>tthompson</RemoteUser>

                <ForwardedFor>67.187.228.183</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">183020</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] ITIL">183011</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/SolidCore/web</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">183014</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/SolidCore/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
