Accession Number:

ADA610360

Title:

Unintentional Insider Threats: A Review of Phishing and Malware Incidents by Economic Sector

Descriptive Note:

Technical note

Corporate Author:

CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST

Personal Author(s):

Report Date:

2014-07-01

Pagination or Media Count:

41.0

Abstract:

The research documented in this report seeks to advance the understanding of the unintentional insider threat UIT that results from phishing and other social engineering cases, specifically those involving malicious software malware. The research team collected and analyzed publicly reported phishing cases involving malware and performed an initial analysis of the industry sectors impacted by this type of incident. This report provides that analysis as well as case examples and potential recommendations for mitigating UITs stemming from phishing and other social engineering incidents. The report also compares security offices current practice of UIT monitoring to the current manufacturing and healthcare industries practice of tracking near misses of adverse events.

Subject Categories:

  • Computer Systems Management and Standards

Distribution Statement:

APPROVED FOR PUBLIC RELEASE