Threats to Information Security ◾ 321
most employees, it is difficult to imagine a fellow employee coming into work every
day under a ruse, but it does happen. As we stated before, employees are responsible
for more successful intrusions than outsiders. It becomes very difficult to find the
source of internal attacks without alerting the attacker that you suspect them of
the wrongdoing. e best line of defense against fraud and theft by your internal
employees are well-defined policies. ese policies can make it easier for the infor-
mation security manager to collect data on the suspected wrongdoer to prove what
bad acts have been performed by the employee.
If you have well-defined policies in your organization, the information security
manager c ...