INFS5115 Security Principles
Questions:
1.
Apply the Kandias et al (2010) insider threat prediction model to the Societe Generale incident (Sayer & Wailgum 2008) to analyse motive, capability and opportunity. Recommend three potential mitigations relevant to the incident.
Kandias, M, Mylonas, A, Virvilis, N, Theoharidou, M and Gritzalis D, 2010, An Insider Threat Prediction Model in proceedings of International Conference on Trust, Privacy and Security in Digital Business, Springer, Berlin, Heidelberg.
Sayer, P and Wailgum, T, 2008, What You Can Learn about Risk Management from Societe Generale: https://www.cio.com/article/2436790/what-you-can-learn-about-risk-management-from-societe-generale.html
2.
Answer the following question in relation to the article by Crozier & Corner (2017):
- Describe the techniques and tools used by the attackers to exfiltrate data, with reference to the classification schemes described in the seminar.
Crozier, R, Corner, S, 2017, Hacked Aussie Defence firm lost fighter jet, bomb, ship plans, itnews, Oct 12, https://www.itnews.com.au/news/hacked-aussie-defence-firm-lost-fighter-jet-bomb-ship-plans-475211
