Advanced Persistent Threat and Insider Threat

0M05549 CT1000988765506998026

4 slides · 1 min read · Domain 8

Slide 1

These are typically "to establish and

A definition for Advanced extend its presence within the information Persistent Threat (APT) is technology infrastructure of organizations presented by NIST as "an

[to] continually exfiltrat(e] information and/ adversary with sophisticated or to undermine or impede critical aspects of levels of expertise and a mission, program, or organization, or place itself in a position to do so in the future...." significant resources, allowing it through the use of multiple

Moreover, NIST adds, "[T]he advanced different attack vectors (e.g., persistent threat pursues its objectives cyber, physical, and deception), repeatedly over an extended period... to generate opportunities to adapting to a defender's efforts to resist it, and with determination to maintain the achieve its objectives." level of interaction needed to execute its objectives."

Adversaries include nation states, activist groups, and criminal groups. Published industry reports have identified technology, energy, financial, and healthcare among sectors frequently targeted by adversaries. Tactics deployed by the threat actors constantly change and evolve.

Insider Threat

The term insider threat should not be strictly interpreted as employees who intend to directly harm the organization through theft, sabotage, or other means. Statistics and reports from industry indicate that ignorance and negligence (and not necessarily malicious intentions) are also a major cause of security breaches and incidents.

With this point established, a reference to insider threat could include employees or former employees, contractors or business associates, and those with inside information on organizations' processes, practices, or data, among other things. Simply put, these insiders are generally more aware of potential abuse vectors.

Test this domain