zlacker

[parent] [thread] 1 comments
1. daxelr+(OP)[view] [source] 2017-02-28 17:41:20
How does the threat model where employees are the enemy differ from the threat model where malware running inside the network is the enemy?
replies(1): >>simias+M1
2. simias+M1[view] [source] 2017-02-28 17:50:50
>>daxelr+(OP)
You want your employees to collaborate with you avoiding and tracking down malware and potential leaks. If everybody is used to working around your restrictions you just make it harder for you to figure out what's happening when something goes wrong.

For instance if your policies are too restrictive people will use their smartphones more and more to access the internet. Then some will start doing work stuff on their smartphones and you lose all control. What do you do then? Forbid smartphones within the company? Fire everybody you catch using one? It's just an arms race at this point.

Sane security measures and some pedagogy go a long way. Easier said than done though, it's a tough compromise to make.

[go to top]