1 / 101100%
Exploring Data Security Management Strategies for
Preventing Data Breaches
Section 1: Foundation of the Study
Background of the Problem
In the field of information technology (IT), humans and security are two entities
which work together to ensure the safe and smooth operation of a system. Any shift in
either component will offset this balance and cause disruption. One of those changes, on
the human side of the scale, is an insider threat. Insider threats cost the average American
firm $15.4 million per year (U.S. Department of Justice, 2015). A National Institute of
Standards and Technology (NIST) survey revealed 20% of data breaches result from
insider threats (NIST, 2011). Insider threats pose a serious problem to the organization by
exploiting trusted relationships between humans and data.
Data exfiltration is one of the byproducts of insider threats. Per Schlicher,
MacIntyre, and Abercrombie (2016), data exfiltration involves transporting data from
within an organization to an entity outside of the organization. Additionally, partners and
vendors are additional factors due to the collaborative nature of IT architecture today. As
echoed by Quigley (2002), these relationships of organizations enable access to internal
systems for suppliers and partners alike.
Recent research studies conducted on insider threat and how that relates to data
breaches focus more on the reactive side of the fence, versus proactive. Liu, Shu, Yao,
and Butt (2015) emphasized the importance of ensuring data transmitted and stored,
especially in cloud solutions and is protected from data leaks. The technique involved a
scan of the data in a target cloud solution using optimized algorithms to detect data leaks.
Once a leak is detected using big data technology, encapsulation is performed by
transforming the leaked data identified to ensure information about the detected leak in
itself does not become a risk. Lamba, Glazier, Schmerl, Pfeffer, and Garlan (2015) sought
to create a clustering algorithm that combines contextual information and current data
exfiltration events to determine if a data breach has occurred. The deficiency of this is the
lack of strategies presented from the lack thereof of solutions to deter and prevent insider
threats. More so, the idea will be to potentially use the findings of this study to contribute
to the exploration of a solution that may be usable as a standardized framework in the IT
industry.
Problem Statement
There is a lack of strategies for securing data from unauthorized trusted insiders.
Researchers have found that a majority of small-scale IT government contracting firms do
not place appropriate emphasis and investment in securing data from unauthorized trusted
insiders (Densham, 2015). A large share of the $4.63 billion losses incurred by victim
companies, attributes to data breaches by malicious insiders (Internet Crime Complaint
Center, 2016). The perpetuation of this type of crime continues to ravage organizations of
all sizes and sectors, causing security and economic concerns for companies and clients
due to the dangers of sensitive information leakage. The general IT problem is that data
breaches caused by malicious insiders are still prevalent due to the lack of data security
management strategies. The specific IT problem is that some database and system
administrators lack data security management strategies to prevent data breaches by
malicious insiders in small-scale IT government contracting firms.
Purpose Statement
The purpose of this qualitative multiple case study was to explore the data security
management strategies that database and system administrators use to prevent data
breaches by malicious insiders in small-scale IT government contracting agencies. The
targeted population is database and system administrators of three small-scale IT
government contracting agencies along the northeast region of the United States that have
data security management strategies. The implication for positive social change is that by
reducing data breaches, the unauthorized disclosure of consumers’ sensitive information
may subside, thereby preventing cases of identity theft and securing and preserving
business secrets and reputation.
Nature of the Study
After considering the three methods of research, qualitative, quantitative, and
mixed methods, I selected qualitative research methodology for the research study. The
qualitative approach helps to gather information and obtain an understanding of human
behavior and perspectives (Houghton, Murphy, Shaw, & Casey, 2015). This study
explored the human behavior and perspectives of database and system administrators, and
the data security management strategies they use to prevent data breaches by malicious
insiders in small-scale IT government contracting agencies; therefore, the qualitative
method is appropriate for this study. Quantitative research gathers quantifiable data
needed for statistical analysis through the evaluation of relationships between variables,
and the validation or invalidation of hypotheses (Gray, 2013). Because my study does not
attempt to validate a hypothesis, I chose not to use a quantitative method. Mixed methods
research includes both qualitative and quantitative research elements (Mayoh &
Onwuegbuzie, 2015). I did not choose the mixed method because I eliminated the
quantitative approach. Therefore, I determined that the qualitative approach best suited
my study.
Four qualitative research designs: case study, phenomenology, ethnography, and
narrative were considered as the research design for this study. The case study research
design was considered and chosen as the most suitable design for this study. Researchers
use case study research design to conduct probing research by asking how and why
questions to gain a deeper understanding of real-life situations in their naturally occurring
setting (Bölte, 2014). Because the intent of this study is to understand and describe
strategies used by database and system administrators to prevent data breaches by
malicious insiders, the case study research design, specifically, a multiple case study
research design, was the most appropriate to inform this study. Another research design
considered was phenomenology. Sousa (2014) explained that phenomenology focuses on
how research participants experience, live through, or infer the research study topic.
Because the focus of the study is not on how the participants lived through the
experience, phenomenology design is not the chosen research design. Ethnography was
another research design considered. Ethnography design focuses on context or
culturebased research of a specific group and targets the shared patterns of a particular
culture (Small, Maher, & Kerr, 2014). The intent of this study is not to study any culture,
ethnicity, geographical location, or group; therefore, using ethnography will not meet the
goal of this research study. The narrative research design was another viable option
within the qualitative methodology. The narrative research design intends to create
meaning through interview responses and concluding them with a story that broadens
life’s meaning (Grbich, 2015). However, the intent of this study is not to qualify life, but
to focus on the data security management strategies used by database and system
administrators to prevent data breaches by malicious insiders. Therefore, the narrative
research design is not the choice for the study.
Research Question
What data security management strategies do database and system administrators
use to prevent data breaches caused by malicious insiders?
Interview Questions
I conducted semi structured interviews with the participants of my study to
explore data security management strategies they use to prevent data breaches by
malicious insiders. The interview questions are open-ended to allow the researcher to
capture as much information from each participant as possible. Appendix A contains the
12 interview questions I asked each participant of my doctoral study.
Conceptual Framework
I selected the general systems theory (GST) as the conceptual framework for the
study. In 1937, Von Bertalanffy (1972) introduced the GST. Later in 1949 and 1972, Von
Bertalanffy developed the theory further and revamped it, respectively. The GST focuses
on the study of the interdependence of modules rather than the models working in
isolation. Over the decades, Von Bertalanffy’s GST has contributed significantly to many
disciplinary fields, including philosophical, and extensible to the complete set of sciences
(Pouvreau, 2014). The GST approach provides a robust framework for security (Young &
Leveson, 2014). Drack and Schwarz (2010) noted that key constitutes of the GST include
function, structure, and process, which are the critical constructs to help inform this
research study. Function pertains to the order of processes within the system and relates
to how system components interact. Structure refers to a system component that is
thoughtfully instituted, such as a business enterprise, or order of the various parts of an
organization, among others. The process relates to the activities and dynamics that go on
within the system to preserve it or cause a change.
As related to this study, the key constructs comprise a system, that is small-case
IT contracting firms. Within the system, input functions include data security
management strategies used by database and system administrators. This is a process that
secures data from data breaches by a malicious insider and output functions or the
prevention of data breaches by malicious insiders due to more secure systems. From a
structure point of view, a cross-sectional analysis of participant organizations structures
could help inform the study by identifying areas of improvement from one institution to
the other. Processes implemented from one organization to another may help detect key
data security management strategies. This may help to close gaps that allow malicious
insiders to exploit. GST aligns with this study exploring data security management
strategies to secure data that may result in reducing data breaches, and the unauthorized
disclosure of consumers' sensitive information will subside; thereby preventing cases of
identity theft, securing business secrets and preserving the reputation of an organization.
Definition of Terms
Anomalies: Anomalies are states of behavior that are unusual and deviate from the
expected or norm (Goldberg, Young, Memory, & Senator, 2016).
Computer-readable extracts: Computer-readable extracts (CREs) are exports of
data from information systems that hold some level of classified data (U.S. Department of
Homeland Security, 2012).
Cybercriminals: Cybercriminals are individuals who use information and
communications technology (ICT) to commit a crime, usually for personal gain, and are
responsible for data breach incidents targeting organizations (Li, Yin, & Chen, 2016).
Data breaches: Data breaches are incidents that result from unauthorized access
to data, compromising data confidentiality, integrity, and availability (Sen & Borle,
2015).
Database administrator: The database administrator or DBA role comprises the
use of specialized software to organize and store data and ensures that data are available
to authorized users and secured from unauthorized access (U.S. Department of Labor,
2018a). For the purposes of this study, the database administrator role encompasses
personnel with job titles such as but not limited to database management specialist,
database specialist, database architect, manager of database administration, database
manager, database designer, database analyst, data administrator, data center support
specialist, data quality manager, database engineer, and informaticist, among others.
Insider threats: Insider threats are current or former employees, contractors, and
other interactors of the system with privileged access, and can circumvent security
mechanisms in place, steal valuable information, and cause damage (Jingguo, Gupta, &
Rao, 2015).
Malicious insiders: Malicious insiders are current or former users of a system who
has or has authorized access and has intentionally or accidentally violated system policy
that adversely affected the confidentiality, integrity, or availability of a system (Nostro,
Ceccarelli, Bondavalli, & Brancati, 2013).
Personally identifiable information: Personally identifiable information (PII) is
any piece of information that is used solely or in conjunction with other information to
identify an individual by direct or indirect inference (U.S. Department of Homeland
Security, 2012).
System administrator: The system administrator or sysadmin role ensures the
dayto-day operation and management of the computer systems of an organization (U.S.
Department of Labor, 2018b). For this study, the system administrator role encompasses
personnel with job titles such as but not limited to network systems administrator,
security systems administrator, application administrator, system architect, and systems
engineer, among others.
Trusted partners: Trusted partners are any business partners that have authorized
access to a system (Caruso, 2003).
Assumptions, Limitations, and Delimitations
Assumptions
Assumptions are unconscious, socially-shared beliefs, knowledge, and
conventions believed to be accurate but may not be real (Atkinson, 2017). For my
doctoral study, I made some assumptions. I assumed that an efficient way to retrieve the
data needed to answer my research question is to use the qualitative research method. I
expected that my participants would understand the interview questions and responded
honestly based on their knowledge and experience. Also, I assumed the number of
participants would be enough to reach data saturation and reflect an accurate
representation of the population sample. I ensured the knowledge and experience of my
study to the best of my ability when collecting their participant eligibility information
before the interviewing phase. I used open-ended questions in the semistructured
interviews to allow participants to provide a considerable assessment with their responses
rather than yes-or-no answers.
Limitations
Limitations in research studies allow researchers to communicate problems of
their research study, and provide awareness of those problems to research reviewers, as
well as discuss how to address those problems in the study (Allen, 2017). Limitations to
research studies may not be intentional. The study did not include large-scale
organizations; instead, I explored data security management strategies used by database
and system administrators at small-scale government contracting firms. Data security
management strategies of small-scale government contracting forms may differ from that
of larger firms. Another limitation of my study was that the sample population of
database and system administrators encompassed those who have experience and
knowledge on questions I asked during the semistructured interviews around data security
management strategies. The lack of experience in or around a specific subject merited no
data collected on those themes and topics. Also, I anticipated that the use of qualitative
research methodology might introduce bias on my part, or by my participants.
Delimitations
Delimitations refer to the confines and context of the research study that is within
the control of the researcher (Carson, Gilmore, Perry, & Gronhaug, 2001). The chosen
geographical location for my research is the northeastern region of the United States;
therefore, I only interviewed participants in this specific geographic area. Thus, the
geographic location is a boundary set for this study. The constraints placed in my study
isolated it to a particular population of the sample. The data collection may, therefore, not
be a general representation of all cases in larger firms or other nongovernment
contracting firms. Additionally, the nature of the chosen research design, a multiple case
study, would not lend itself to ensuring external validity as case studies are restraining to
the specific environments wherein the event occurred.
Significance of the Study
Contribution to Information Technology Practice
The significance of this research study will reside in the effort to explore data
security management strategies whereby database and system administrators of
smallscale IT government contracting firms can implement to prevent data breaches by
malicious insiders. The response cost invested by database and system administrators to
react to data breaches by malicious insiders are expensive (Posey, Roberts, & Lowry,
2015). Furthermore, the findings of the study might assist database and system
administrators in preventing and addressing gaps in data security management strategies
to prevent data breaches by malicious insiders. Data from this study might assist database
and system administrators in identifying best practices to avoid data breaches proactively,
giving back time and peace of mind, while helping their organizations to save on cost
incurred from reacting to data breaches.
Implications for Social Change
The implication for social change is that by reducing data breaches, the
unauthorized disclosure of consumers' sensitive information may subside, thereby
preventing cases of identity theft, and securing and preserving business secrets and
reputation, respectively. The results of the study might contribute to social change by
shedding light on data security management strategies which when implemented
especially in small or large scale government information systems, may prevent data
breaches by malicious insiders that could potentially lead to espionage, identity theft,
trade secrets exposure, and cyber extortion, among others. Securing data is a costeffective
solution, and a must for organizations to prevent or reduce the risk of impact from
breaches caused by insiders, which is more severe than that by outsiders as insiders have
considerable knowledge of the data stored (Ho-Jae, Min-Woo, Jung-Ho, & TaiMyoung,
2015). The damage caused by data breaches could ruin the reputation of an organization
and incur legal ramifications.
A Review of the Professional and Academic Literature Data breach
incidents continue to cripple organizations of all sizes due to a variety of reasons, such
as the lack of data security management strategies to prevent malicious insiders from
perpetuating data breaches. The reason for this continuous trend is due to the value of
data today. Claycomb (2015) argued IT practitioners must recognize current trends as
an important aspect of ensuring systems remain secure. Therefore, like keeping up with
trends in the field of IT, defenders of information systems need to keep abreast of new
capabilities, which could be exploitable by malicious insiders. Data is the fundamental
and crucial element in systems used by IT enterprises. Therefore, my doctoral study
research topic focuses specifically on safeguarding data, and not network browsing, or
file access activities. In my review of the professional and academic literature, I discuss
the GST, as well as establish grounds to use as a foundation for conducting my study
(Liang, Biros, & Luse, 2016). Additionally, I relate these concepts to the research
question of my study: What data security management strategies do database and
system administrators use to prevent data breaches caused by malicious insiders?
From the literature reviewed, I discovered a variety of data management security
strategies are already at the disposal and in reach of database and system administrators,
although each implementation is different. I also noticed from reviewing the literature
over and over that these four themes were reoccurring (a) the impact of data breaches to
companies, consumers, society, and nation; (b) data security management administrative
strategies; (c) data security management technical strategies; and (d) professionals’ view
on data security management. Therefore, the literature review for my study is based on
these four themes.
The literature review spans across multiple years, that is, literature published
within five years of my anticipated graduation date (2019), and are relevant to the
research topic, to encompass growth and trends in this doctoral study. I ensured the
articles are peer-reviewed by using Ulrich’s Periodicals Directory. The primary sources
for my journal articles include the following research databases: Association for
Computing Machinery (ACM) Digital Library, EBSCOhost Computers, and Applied
Sciences Complete, IEEE Xplore Digital Library, ProQuest database, and Google
Scholar. From the review of the literature, I found there was a gap in literature covering
the use of a holistic data security management strategy that encompasses both technical
and administrative data security management strategies. The prior literature contains
technical or administrative strategy and not both; therefore, it does not portray a holistic
strategy. In addition, some literature discussed strategies from a proactive stance and
others from a reactive posture, but none of them addressed a combination of both. In
summary, of the 12 papers relevant to this study, none of them sufficiently addressed data
security management strategies in use by database and system administrators to prevent
data breaches by malicious insiders.
As compared to other forms of cyber-attacks on the rise, the exponential growth of
data breaches has a significant impact on organizations, and malicious insiders are the
perpetrators to a sizable portion of these data breach accounts. In a review of the causes
of data breaches, I observed that there are various manifestations and motivation factors
of malicious insiders who perpetrate this crime. As suggested by Posey et al. (2015),
some of these motivation factors are discoverable late. However, the proactive
mechanism may be put in place to prevent or minimize breaches altogether, such as the
use of proactive administrative and technical controls (Korpela, 2015; Padayachee, 2015).
Both administrative and technical data security management controls complement each
other and bring to a full cycle the three components of organizations: people, process, and
technology.
Large volumes of research efforts are underway to gain a better understanding of
some of the motivational factors of malicious insiders, but that is not the focus of this
study. Burns, Posey, Roberts, and Lowry (2017) predicted behaviors of malicious
insiders. Cates (2015) discussed the motivations of malicious insiders, which includes
financial gains from the sale of financial information, personally identifiable information,
and critical intellectual property. Both Cates and Burns et al. addressed the human aspect
of the triad but may not be enough to prevent data breaches by malicious insiders;
therefore, a combination of strategies that satisfy all three elements of an organization
may be vital. To predict the risk to organizations from a data breach attack, additional
components such as the use of the Bayesian belief network are introduced (Sticha &
Axelrad, 2016). Having considered the inevitable, data breaches are bound to occur (Cho
& Lee, 2016); therefore, the focus of this study is to gain a better understanding of data
security management strategies implemented by organizations to prevent data breaches
by malicious insiders.
The General Systems Theory
The purpose of this qualitative multiple case study is to explore data security
management strategies that database and system administrators use to prevent data
breaches by malicious insiders. In my literature review, I discussed GST as the
conceptual framework as it related to the focus of my literature review. The research
question was: What data security management strategies do database and system
administrators use to prevent data breaches caused by malicious insiders?
To explore the research and assess my discoveries through foundational content,
past and current research, and trends and innovations in information security, I used the
GST as the conceptual framework for the study. Von Bertalanffy (1972) developed the
GST from which the system theory originates from. The GST focuses on the nature of
complex systems and is a framework researchers use to explore or describe the
interdependence of objects working together to yield some result rather than the objects
working in isolation. Fundamental tenets of the systems theory include (a) objects or
variables within the system, (b) system and object attributes, (c) the interrelationships
existing between objects within the system, and (d) the presence of the system within an
environment. The GST approach provides a robust framework for understanding the
complexities of a system (Schneider, Wickert, & Marti, 2017); hence, it will support
exploring data security management strategies used by database and system
administrators to prevent data breaches caused by malicious insiders.
The GST is applicable to this doctoral study. The constructs align well with
information systems within organizations, and the data stored in these systems. Data
security management strategies align with attributes of the information system. Another
attribute alignment is the movement of data into, from, or within the system. The
presence of data consumers indicates the use of information systems within an
environment. From a structural perspective, systems theory provides a lens from which to
explore the relationship between data security management strategy, provisioned by
database and system administrators to secure organizational data.
The Evolution of the General Systems Theory
The GST explains that systems are comprised of individual subsystems that work
together as a whole. In the use of the analogy of the system theory as a premise, a car is a
system; however, the separate car parts do not define the car as a system on their own.
The various parts assembled and working units make up the car system. Therefore, Von
Bertalanffy (1972) asserted in the definition of a system, the individual subsystems
should not be used to describe the system, but a comprehensive approach should be used.
Over the years, there have been significant contributions to the systems theory.
Kast and Rosenzweig (1972) discussed the need to review the study the complexity of
systems in both science and technology rather than the analysis of a system. In a study of
the generations of complexity theories, Alhadeff-Jones (2008) pointed out contributions
made by Morin in 1977 and 1980, as well as Moignein 1990, that challenged the inherent
nature of the system theory to be linear, and hierarchical, among other epistemological
legitimacy facets. Ceric (2015) described systems theory as a method that enables the
holistic understanding of the interdependencies between the elements of a system, which
is critical to evaluate and manage the target system successfully. An application of the
system theory is a derivative of it called the general technical system theory in which a
system plays a specific role in the general functions within an environment such as
performing a function of transferring human inputs, materials, energy or signals to the
output of humans, materials, energy or signals (Wang, Zhang, & Wang, 2016).
Supporting Theories
Multiple theories could be used from different viewpoints to perform a research
study on data security management strategies to prevent data breaches. Theories such as
the soft systems methodology (SSM), open systems theory (OST), and theory of planned
behavior (TPB) have been used as the conceptual framework in other researches on data
breaches in organizations caused by malicious insiders. The supporting theories noted
depict their purposes and how they can be used as the lenses to explore the research
question for my study, although I did not choose them as the conceptual framework for
this study. I chose the GST to explore data security management strategies in use by
database and system administrators to prevent data breaches caused by malicious insiders.
SSM is one supporting theory of GST. The SSM is described as a technique used
to solve complex and unclear problems (Fitroh & Utama, 2017). SSM was developed by
Checkland and involves the use of a series of stages to evaluate a phenomenon to obtain a
holistic view. Four various kinds of activity are used in the SSM model, including finding
out the problematical situation, making purposeful activity models relevant to the
situation, using the models to question the situation, and defining or acting to improve the
situation. A mnemonic often associated with SSM is CATWOE, which stands for
customers, actors, transformation process, Weltanschauung, owners, and environmental
constraints. SSM supports GST as it focuses on the impact of an action or lack of thereof
of actors within a system and how the existing association between entities in the system
are affected.
OST is a supporting theory of GST and was developed after the second world war.
In a study to explore the interconnection of the GST and OST in 2015, Norman
determined the use of the GST allowed the identification of the components of the
phenomenon under study, whereas the use of the OST helped to understand how the
system influences system-related entities. Malecic (2017) argued that it is vital for
researchers to understand systemness as a characteristic of GST and identify where to
find it in life applications. Understanding the inputs, internal process, and outputs of a
system allow researchers to grasp an in-depth understanding of the phenomena under
study. OST supports GST as it posits that systems are strongly under the influence of
their environment.
The TPB is another supporting theory of GST. TPB was instituted and revisited by
Icek Ajzen in 1988 and 1991, respectively (Ajzen, 2004), to help understand how to
change the behavior of people. Researchers use theories to allow the exploring of a
phenomenon or answer a research question from the perspective of the theory using that
as the lens through which to view a phenomenon (Hasking & Schofield, 2015). TPB
posits that the outcome of a specific behavior is based on the intentions of that behavior
resulting from subjective norms, attitudes, and behavioral control perceived. TPB allows
researchers to link the belief and behavior of a phenomenon through predictability. Sutton
and White (2016), used TPB as the lens to predict sun-protective intentions and
behaviors. TPB supports GST as it focuses on investigating factors associated with an
entity based on what is believed.
Another supporting theory of GST is the critical systems thinking theory. Critical
systems thinking theory is known to have roots in soft systems theory. Critical
components of the systems thinking approach are its critical stance against inclusion and
exclusion factors constituting the problem settings under review, and utilization of
various systems methods based on the characteristics of the situation encountered (Flood,
1990). Critical systems thinking theory comprises the integration of critical theory and
practice in systems that may be diverse and advises how best to use such systems.
Contrasting Theories
Grey systems theory is a contrasting model to the GST. The grey systems theory,
established by Julong Den in 1982, operates under four models: even grey model, original
difference grey model, even difference grey model, and discrete grey model (Liu & Lin,
2010). Liu, Yang, Xie, and Forrest (2016) suggested that researchers use grey systems
theory, especially in situations where available information is incomplete, and the data
collected lacks accuracy. The aim of grey systems and its application is to link social
science and natural science and may also be used to determine the probability of
occurrence of incidents, due to the difficulty in making that determination with certainty
(Omidvari, Abootorabi, & Mehrno, 2016). Unlike the GST, where elements of a system
are known, grey systems lack information, such as behavior document, structure message,
and operation mechanism. The differences between the grey systems theory and systems
theory are substantial that the two theories are in contrast.
General Systems Theory Applied to Data Security Management
Von Bertalanffy (1972) described systems theory as the study of the
interdependence of modules within a system rather than the models working in isolation.
The systems theory is a central theory used in the investigation of systems not only in a
modular fashion but as a whole due to the interaction of the individual components that
make up the system (Bridgen, 2017). System theory views a system in its completeness
and the relationships between the various subsystems constituting the whole system (Von
Bertalanffy, 1968). In a study of modeling to deter insider threats, Casey, Morales,
Wright, Zhu, and Mishra (2016) found that the in-depth look at the interaction between
senders and receivers in a system presents great insight into the static or dynamic nature
of information with which an organization can build simulations and parameters to learn
insider behavior. Similarly, this study intends to explore the interactions within a system
to obtain insight into the effects of the various components on each other, as well as on
the system as a whole.
The critical components of the systems theory are (a) objects within the system,
(b) attributes of the objects within the system, (c) the relationship between the system
objects, and(d) the presence of the system inside an environment (Von Bertalanffy,
1968). As this related to my doctoral study topic, (a) the organization and the information
systems are objects, (b) data security management strategies are attributes, (c) data
residing within information systems connected to the network of the organization
represents relationships, and (d) information systems containing data within the
organization depicts the presence of a system inside an environment.
I chose the systems theory as the lenses for my doctoral study to explore data
security management strategies used by database and system administrators within an
organization, the threats of malicious insiders to cause data breaches, and the outcomes of
implementing the specific strategies to deter and prevent data breaches. To understand
and explore the relationship between the components of my study: database and system
administrators, information systems, data, malicious insiders, and data breaches, in the
context of my study, a relationship exists between all four components.
Like managing any shop, taking an inventory of and defining what is in stock is
the right place to start. Likewise, information systems hold a variety of data, including
personal data, confidential data, geographical data, images, and financial data, among
others. Performing this type of planning activity provides visibility into data areas that
may not have been transparent and well understood, leading to the development of a
holistic data security management strategy that encompasses all data areas. The laws and
regulations that govern organizations have an influence on the type of data classification
in use. Zhurin (2015) asserted a variety of regulatory documents at the disposal of
organizations could be used as part of their strategy to prevent insider threats. Some of
the laws and regulations implemented are a result of threats and impacts from the
international community (Atkinson, 2016). Compliance with such laws fosters
international relationships, meaning international help is accessible in times of need.
The process of defining organizational assets, especially data around personnel,
process, and technology, it is vital to determine the resources that require protection, the
value, and classification based on priority. Attributes such as the location of the data
element, the type of asset associated with that piece of data, the classification level such
as whether the data is personally identifiable information (PII), sensitive PII (SPII), or
protected health information (PHI), among others, needs consideration, while keeping in
mind the cost and effort value . Also, Bakar and Selamat (2016) asserted it is crucial to
consider how data is used primarily in crowdsourcing information systems to preserve
data confidentiality.
Performing the act of determining risk levels and classification of data will ensure
the appropriate classification of data and risk level, to ensure association of the right level
of emphasis on data that has little to no impact on the organization should there be a
compromise. Kenney (2015) suggested another side of the coin to this aspect of data risk
assessment and classification is the importance of gaining an understanding of the diverse
types of potential threats to organizational data. Setiawan and Sastrosubroto (2016) found
that in circumstances where a layered security strategy is in use, organizations stood a
higher chance of deterring and preventing data breaches by malicious insiders. Alongside
planning and classification of the risk of data, if compromised, it is vital for organizations
to assess the impact and threats that may come with their data.
Data Security Management Explained
The information security triad: confidentiality, integrity, and availability play a
vital role in the establishment of a data security management strategy within an
organization. As suggested by Moghaddasi, Sajjadi, and Kamkarhaghighi (2016), data
security management ensures the identity of the source or sender of data, the integrity of
the data, and the identity of the destination or receiver. The assurance and control
afforded by data security management allow for flexibility and expansion with the
evolution of ICT, ensuring new features or areas are brought under the umbrella of an
organization’s data security management strategy. Data stored in systems come in a
variety of forms. For instance, in the study performed by Razaque and Rizvi (2016), the
data is stored in a cloud storage system, whereas the data reviewed in the study by
Shalev, Keidar, Moatti, and Weinsberg (2016), reflect the use of security controls to
protect data stored on-premise; however, despite the location of the data storage, the level
of damage of a breach is the same. Establishing a mechanism to monitor and detect
insider threats by malicious users, accessing data, and combining this information with
other established insider threat solutions, may provide an organization with a more
revealing insight into the posture of the security policies and controls around the security
of their data.
Data Security Management Conceptual Model
From a technical strategy point of view, based on the reviewed literature, the
aspect of the IT industry focusing on data security management continues to make long
strides to enhance the strategies used by database and system administrators to prevent
data breaches by malicious insiders. For instance, in both government and private sectors,
smart cards are in use by personnel to increase the authentication factor level of
privileged users. Despite known vulnerabilities with smart card and password
authentication are exploitable through an attack known as privileged insider attack, where
obtained private key credentials could be used to impersonate access to a system,
twofactor authentication in general provides added protection to the authentication of
personnel (Wang, D., Wang, N., Wang, P., & Qing, 2015). Authentication plays a key
role in the protective mechanisms that an organization can use to prevent data breaches
by malicious insiders. Also, personnel background checks are more intense, and at more
detail than ever before, to ascertain new hires and employee personnel clearance renewals
are adequately performed before entrusting them with classified information.
Another observation made during my review of the literature related to my research topic
is that most of the researchers leveraged the general system theoretical framework. Also,
most of the researchers conducted their work using case studies, and data provided to
them by a partner or some form of collaboration with a more extensive IT establishment
or entity. For instance, the research conducted by Shalev et al. (2016) involved gaining
access to the database of the IBM Research IT department.
Aspects of the topic that have been researched include (a) the setup of an auditing
mechanism to monitor privileged user behavior and isolating any anomalies for further
review; (b) the identification and establishment of a baseline either by previous behavior,
canned roles, or peers; and (c) the proactive detection of insider threat based on a specific
policy, or the behavioral pattern of a known insider threat (Agrafiotis, Erola, Goldsmith,
& Creese, 2016).
Aspects of the topic that needs to be researched further, according to the reviewed
articles include (a) the implementation of the identified solutions in a large-scale
environment, (b) the elevation of a role by nonprivileged users through collusion, (c) the
lack of a cross-platform solution for enterprises with a hybrid architecture of operating
systems (Lamba et al., 2015), and (d) the lack of an automated mechanism to temporarily
disable infringing accounts.
Based on the literature review, held assumptions existing within the field include
the general notion that only privileged users can pose insider threats to organizations.
Also, there is a vague notion that users of systems are security savvy, and educating
personnel on security awareness is not a priority. Education on other aspects of security is
prevalent today. However, education specifically on the topic of the insider threat is
lacking. Educating users about early indicators of insider threat and providing
information on the communication channels to use for reporting suspicious malicious
insider behavior confidentially, could help reduce the likelihood of insider threat
occurring.
Insider Threats Explained
From the literature review conducted, a held assumption that exists in some IT
organizations is the general notion that only malicious privileged users could become
insider threats, ignoring the need to train and educate the nonprivileged personnel,
making them more vulnerable to vectors such as social engineering, whereby malicious
staff could collude with them or take advantage of them. The lack of education and
training of users on how to handle and report suspicious activity could also contribute to
factors leading to data breaches.
Insider threats could take a variety of forms, resulting in varying magnitudes of a
threat to companies. Per Legg, Buckley, Goldsmith, and Creese (2015), three main
categories of insider threats include the following: IT sabotage, theft of intellectual
property, and data fraud. Each of these categories affects the victim organization in a
significant way, for some at a higher magnitude than others. Irrespective of the class,
Zaytsev, Malyuk, and Miloslavskaya (2017) suggested insider threat can be subsided with
the use of strategies, including behavioral models that develop a taxonomy for insiders,
attacks, countermeasures, the study of organizational threats with the development of
forecasting models, and, early detection techniques. The latter is made possible via the
use of technical tools.
Insider Threat Attack Schemes
The threat of malicious insider activity may stem from current employees,
previous employees, contractors, or third parties, including organizational partners and
vendors. Each of these entities interacting with or within the organization can cause
devastation to the organization. The root cause of insider threats is either accidental or
malicious. Some organizations find it challenging to secure their enterprise data from
cybercriminals. Continuous monitoring and auditing mechanisms are implemented to
help detect and report activities by cybercriminals. While these measures have proven to
be effective in protecting data from external intruders, some organizations continue to
face challenges such as unauthorized access and use of data by insiders, such as altering
data through unapproved means (Sallam & Bertino, 2017), and the unauthorized use of
CREs. Cheng, Liu, and Yao (2017) concluded that the effect of the data breach, whether
intentional or accidental could pose a severe threat to an organization, including
reputational damage and financial losses, among others. The focus of my study is on the
latter; that is, preventing data breaches resulting from malicious insiders by exploring
data security management strategies are in use to prevent malicious insiders from causing
data breaches.
The Impact of Data Breaches on Companies, Consumers, Society, and Nation
The dependency on data in today’s information age is high compared to previous
eras. Data collection is in amass, from organizations capturing information about their
clients to national security information, which, if compromised, can cause irreversible
damage to a nation. Knowledge of the impact and threats of data breaches to
organizational data may help prioritize the areas of focus when planning for
countermeasures to apply for a defense-in-depth strategy. Gaining an understanding of
the type of architecture and infrastructure in use will allow the database and system
administrators to make an informed decision on the security strategies to implement to
secure organizational data. The use of a risk matrix, organizations would be able to assess
the probability and impact the breach of a specific classification of data could have not
only on the organization but also in the case of stolen PII or PHI, clients whose
information was compromised.
Phillips, Mazzuchi, and Sarkani (2018) studied the risk of vulnerabilities and
defects in context is minimizable by ensuring security and resiliency of the system
architecture, including software, hardware, and other components. Also, a business
impact analysis based on the data from the prior data risk assessment and classification
would provide insight into the impact a data breach would have on the organization and
clients. Rao and Selvamani (2015) concluded it is imperative for organizations to assess
the impact an environment may have on their organizational assets prior to use. The
information gathered and assembled from the planning would serve as input in the
devising of a layered strategy to protect organizational resources.
Data Security Management Technical Strategies
Technical controls are one of two classes of countermeasures that may be in use
by firms to deter and prevent data breaches by malicious insiders. Technical controls
alone may not be enough to combat data breaches by malicious insiders but may serve as
a layer of defense. One of the more recent technical controls leveraged by firms is the use
of virtualization. Some threats may be more challenging to implement countermeasures
for, such as zero-day vulnerabilities; however, Last (2016) suggested developing a plan
with vendors or system providers to react to such attacks quickly will benefit
organizations. In cases where commercial-off-the-shelf software is in use by an
organization, ensuring the software is patched will not only prevent vulnerabilities from
being exploited but also will provide software warranty and license agreements are
maintained.
About virtualization, some organizations move their infrastructure and operations
to use cloud technology despite the known risks of privacy and integrity (Sulochana &
Dubey, 2015). Cloud solutions are known to offer more flexibility when it comes to data
availability (Dieye, Zhani, & Elbiaze, 2017); however, they are also known to have tenets
on the security of users’ data being the highest priority as well as a concern (Chang &
Ramachandran, 2016). Trends software-as-a-service (SaaS) is a type of cloud technology
that affords organizations the capability to move entire enterprise resource planning
(ERP) systems to the cloud (Saa, Moscoso-Zea, Costales, & Lujan-Mora, 2017).
Outsourcing of data storage and management is another similar strategy used by some
organizations to save on cost. In such situations, data travels across physical geographical
boundaries are now flat due to virtualization and globalization.
The use of encryption is a strategy some organizations use to minimize the threat
of sensitive information at rest and in transit reaching the hands of adversaries. Malicious
insiders can exploit vulnerabilities on a network without having direct access to the data
stored in the systems; hence, the need to secure data, not only at rest but also in transit
(Jung, Valero, Bourgeois, & Beyah, 2015). Encrypting data stored in database systems
alone does not as incorporate a holistic solution without securing data in transit as well.
However, along with some encryption techniques comes issues with performance and key
management. Kumar, Meena, Singh, and Vardhan (2015) concluded the strength of the
encryption strategy is as effective as the management of the key; weak key management
means an elevated risk of compromise. Some encryption solutions incorporate a block
indexing strategy to overcome the issue of performance resulting from the negative
impact of encryption on performance (Yuan et al., 2017). In some encryption solutions,
detecting and minimizing data breaches by trusted insiders is achievable via the use of a
use-once key encryption model (Blasco, Tapiador, Peris-Lopez, & Suarez-Tangil, 2015).
The model entails the use of a key to encrypt sensitive files and disallow retrieval of files
without prior access to other related files. The approach forces the insider to extract more
data than what is needed and, therefore, takes the insider a longer time and increases the
effort required by the insiders. In some cases, the frustration resulting from the length of
time taken to extract information may be too concerning for malicious insiders and may
deter them. Encryption techniques shield the data from unauthorized access and enforce
data confidentiality, and in some cases, nonrepudiation.
In most cases, technical controls are effective in protecting external entities from
protruding the network boundary of an organization. The use of devices includes
firewalls, load balancers, intrusion detection devices, intrusion prevention devices,
honeypots, antivirus, proxy servers, and change detection tools such as tripwire, among
others. The detection of malicious insider activity is known to be challenging to detect
using technical controls. Countless techniques are under consideration to use by some
organizations to help detect malicious insider activity. One such method is the use of a
combination of anomaly detection and signature-based techniques to identify potential
security breaches (Chae, Katenka, & Dipippo, 2016). A combination of techniques
offense a defense-in-depth strategy, offering a more resilient strategy for preventing data
breaches. The addition of administrative strategies to an existing technical strategy offers
more robust solutions to combat malicious insider activity.
Data Security Management Administrative Strategies
Administrative countermeasures are known to be the most effective when it comes
to dealing with threats related to humans, who are also known to be the weakest link in
the information security chain. Andersson and Caporuscio (2016) described
administrative controls as security controls that can do without technical controls and do
not rely on technical or technology controls. Humans or personnel within an organization
may become malicious due to several reasons, including (a) retaliation for culture change
due to being irate, (b) becoming disgruntled due to unresolved organization-related
issues, (c) financial burden, (d) rewards from corporate espionage, and (e) pride in
whistleblowing or sale of trade secrets.
Nostro et al. (2013) described malicious insiders as previous or current users of a
system who has authorized access to the target system and has purposely violated the
organizational policy, leading to an adverse impact on that target system by
compromising the confidentiality, integrity, or availability of the system. Knowing the
traits of malicious insiders is key to developing strategies to deter and prevent them from
carrying out their activities. Known characteristics of malicious insiders include (a) the
unauthorized use of work resources such as the Internet, email, and instant messaging for
personal correspondence, (b) unauthorized upload of proprietary organizational
information to an external drive or a covert storage locally or in the cloud, (c) tailgating
in unauthorized secure areas, (d) working during unofficial hours and unusually
transferring large volumes of data, (e) using social engineering techniques against peers
to gain unauthorized information, (f) conducting phishing attacks, shoulder surfing, and
dumpster diving, and (g) planting logic and time bombs in applications, or creating
unauthorized back doors, among others.
Asset management is a vital strategy an organization may use to protect their
assets. Knowledge of the hardware, software, and devices on the network allows
organizations to detect any deviations from the captured baseline quickly. Having an
executable routine in place on a regular schedule and maintained will provide an
organization with insight into any changes to their infrastructure should any rogue nodes
be set up on their network.
Another countermeasure database and system administrators may include in their
data security management policy is collaborating with the human resources department to
develop profiles on employees that show traits of malicious intent. In a study of design
and validation of the information security culture framework in 2015, AlHogail
determined the need for organizations to establish an organizational culture rich in
information security to impact the security behavior and perceptions of employees. The
use of the structured STOPE (strategy, technology, organization, people, and
environment) framework in conjunction with another framework known as the human
factor diamond, which takes into consideration preparedness, responsibility, management,
and society and regulations, could be used to assess the culture of the target organization
(AlHogail, 2015). Maasberg, Warren, and Beebe (2015) suggested the use of the Dark
Triad personality survey instrument to evaluate new employees, just as the Myers-Briggs
Type Indicator (MBTI) assessment and the Adjective Check List (ACL) are in use to
identify personality and psychological traits, this way organizations can have a closer
view of what goes on in the minds of malicious insiders. As part of the organizational
policy, personnel should retake the Dark Triad personality survey to identify any
anomalies or changes that may have occurred over time.
A well-known strategy database and system administrators implement is a
proactive administrative strategy to counteract malicious insider activity leading to data
breaches is, security education, and training awareness (SETA) programs. Educate
administrators on the need to know the type of data their systems hold, their various
access mechanisms, and personnel authorized to access the system, could be a good
strategy to start (Urciuoli & Hintsa, 2017). Bauer, Bernroider, and Chudzikowski(2017)
concluded organization should focus more attention on the administrative information
security controls of their firm and invest in prevention strategies such as SETA programs.
Measuring the effectiveness of SETA programs is an activity that should not be taken
lightly by organizations. A research study conducted by Hina and Dominic (2016)
revealed there is a relationship between security incidents that occur due to negligence
and the erratic behavior of the target population resulting in insider threats to the safety of
organizational data. On the contrary, a study performed by Hwang and Cha (2018)
revealed the opposite, asserting that the stress resulting from SETA programs leads to
role stress and technostress, resulting in lower levels of compliance intention regarding
organizational information security.
The creation and implementation of an organizational information security policy
(ISP) is another strategy in use by database and system administrators to prevent data
breaches. Ismail, Widyarto, Ahmad, and Ghani (2017) concluded ISP portrays an
organization's stance towards both internal and external information assets needing
protection from unauthorized access, disclosure, destruction, and modification. ISPs
comprise information about the rules and boundaries of operation within an organization
and consequences for violating the rules set forth. Making sure there is a balance and
appropriation for the disciplinary action taken due to employee noncompliance will
prevent sanctions or related punishments from negatively affecting them (Aurigemma &
Mattson, 2017). The method of application of sanctions should be one that promotes a
positive work culture.
Also, it is crucial that the ISP is easy to understand and interpret. Buthelezi, Van
Der Poll, and Ochola (2016) found that clear ISPs facilitate implementation with no
difficulty and avoid misinterpretation and ambiguity, resulting in conformity and
uniformity by personnel across an organization. Management support for a zero-tolerance
policy is an essential facet to ensuring conformity and compliance to ISPs by all staff;
especially, when it comes to cultural elements, and internal processes such as system
development life cycle (SDLC), change control, change management, and release
management, among others.
Knowledge of the life cycle of the types of data in use by organizations would put
them in a better position to ensure adequate strategies are in place to safeguard data
entering the information system of the organization, data stored, as it travels internally
within and externally from the organization due to vendors and partners, among others.
Graves (2017) stated the lack of information about how data flows in, out, and the
reasons put organizations at a higher risk for data breaches due to the lack of awareness
and ability to apply strategies to critical data flow points, which are exploitable by
malicious insiders. It is crucial for database and system administrators to include
strategies to routinely audit and measures the effectiveness of data security management
strategies implemented throughout the life cycle of organizational data (Ramachandran &
Victor, 2016).
About the end-of-life of data in a data life cycle, in situations where third parties
are involved in the destruction of information system storage devices, strategies must be
set in place to conduct a follow-up check with the vendor to ensure the vendor uses
appropriate storage destruction techniques. Dedicated shredding bins should be allocated
to the office space and monitored to ensure unwanted CREs are disposed of correctly. It
defeats the purpose of implementing strategies to protect data within information systems
but fail to safeguard the same data after it leaves the system. Imran et al. (2017) suggested
the use of data provenance to track the origin or last known history of a specific piece of
datum. Using such a technique creates an audit trail on data as it moves throughout or
outside of the environment, in this case, the organization providing the needed insight
organizational personnel could tap into should there be a data breach. In Table 1, I detail
the evidence of the reoccurring themes across the literature I reviewed and included an
entry at the bottom of the table, indicating the strategic themes I intend to cover in my
study.
Table 1
Matrix of Literature Comparison
Author Theme 1 Theme 2 Theme 3 Theme 4
Ali, O., & Ouda, A. (2016) Administrative Reactive
Alihodzic, A., Tuba, E., &Tuba,
M. (2017) Administrative Technical Reactive
Aurigemma, S., & Mattson, T.
(2017)
Administrative Reactive
Bauer et al. (2017) Administrative Reactive
Buthelezi et al. (2016) Administrative Reactive
Chae et al. (2016) Technical Proactive
Chang, V., & Ramachandran, M.
(2016) Technical Reactive
Dieye et al. (2017) Technical Reactive
Forde, E. S. (2017) Administrative Reactive
Graves, J. (2017) Administrative Reactive
Hina, S., & Dominic, D. D. (2016) Administrative Reactive
(continued)
Author Theme 1 Theme 2 Theme 3 Theme 4
Hwang, I., & Cha, O. (2018) Administrative Reactive
Imran et al. (2017) Administrative Reactive
Irfan, M., Abbas, H., Sun, Y., Sajid,
A., & Pasha, M. (2016).
Administrative Reactive
Ismail et al. (2017) Administrative Reactive
Korpela, K. (2015) Administrative Proactive
Kumar et al. (2015) Technical Proactive
Last, D. (2016) Technical Reactive
Maasberg et al. (2015) Administrative Proactive
Phillips et al. (2018) Administrative Reactive
Ramachandran, M., & Victor, C.
(2016)
Administrative Reactive
Saa et al. (2017) Technical Reactive
Sulochana, M., & Dubey, O.
(2015) Technical Reactive
Wagner et al. (2017) Administrative Reactive
Yuan et al. (2017) Technical Reactive
Solutions Implemented by Database and System Administrators
The overall strategies in use by organizations are effective from a general pointof-
view; however, that begs the question of how these high-level strategies trickle down and
apply to database and system administrators in ensuring the prevention of data breaches.
First, technical strategies are as effective as what, when, how, and why specific technics
and solutions are used and managed by database and system administrators. In a nutshell,
the following are some technical solutions in use by database and system administrators:
(a) scaling back excessive privileges, (b) avoiding granting default privileges, (c)
securing media exposure (backups) using encryption and expiration, (d) automating
auditing and monitoring of administrators’ activities, (e) testing patches and releasing in a
well-timed maintenance window, (f) balancing administrators’ workload,
(g) managing and keeping inventory of forgotten databases and backups, (h)
implementing database security controls, (i) enforcing database security plans and
policies, (j) conducting incident response activities, (k) removing dormant database users,
(l) monitoring access patterns in real-time to detect data leakage and unauthorized
transactions, (m) archiving external data and encrypting databases as well as backups, (n)
training database and system administrators on risk mitigation, (o) enforcing database
management best practices, (p) implementing strict firewall rules, and (q) removing
unneeded services to reduce attack surface. In Table 2, I show a classification of the
solutions mentioned as administrative or technical controls, and a corresponding column
showing the purpose of the solution.
Table 2
Classification of Solutions
Solution Classification Purpose
Scaling back excessive
privileges
Technical To ensure the least privilege
permissions and need-to-know is
enforced.
Avoiding granting default
privileges Technical To prevent privilege escalation and
masquerading
Securing media exposure
(backups) using
encryption and expiration
Technical To prevent malicious access to backups
and enforce appropriate backup set
disposal
Automating auditing and
monitoring of
administrators’ activities
Technical To receive notifications of security
incidents close to real-time
Testing patches and
releasing in a well-timed
maintenance window
Technical To ensure vulnerabilities are mitigated,
and minimal to no risk is introduced to
the live production system
(continued)
Solution Classification Purpose
Balancing administrators’
workload Administrative
The evenly distributed workload of
database and system administrators
prevents burnout. In a way, this strategy
enforces the separation of duties, which
is a role-based access control
mechanism. Therefore, balancing of
workload reduces the number of
permissions to be managed within a
system (Ultra & Pancho-Festin, 2017)
Managing and keeping an
inventory of forgotten
databases and backups
Administrative
To ensure that any form of access and
retrieval is accounted for. Unauthorized
or out-of-norm behavior, which could
be an indication of malicious activity,
could be easily identified by reviewing
access logs for inventoried databases
and backups
Implementing database
security controls Technical
To ensure confidentiality, integrity, and
availability of database management
systems to ensure the appropriate levels
of access and permissions are assigned
to application and human accounts that
connect to and use database
management systems
Enforcing database
security plans and
policies
Administrative
and Technical
To ensure routine checks are performed
to uncover any deviations from a
documented system baseline such as in
a System Security Plan (SSP) are
reviewed and justified. Also, enforcing
database security policies ensures
compliance with regulations that may
be governing an organization. Some
examples of industry-based controls
include Center for Internet Security
(CIS) benchmarks, NIST special
publication (SP) 800-53 controls, and
DoD Defense Information System
Agency (DISA) Security Technical
Implementations Guidelines (STIGs)
Administrative To ensure that database and system
Conducting incident and Technical administrators, as well as the incident
response activities response team clearly understand their
roles and responsibilities, as well as the
Solution Classification Purpose
courses of action to be taken when an
incident occurs
Removing dormant
database users
Technical To ensure that users who no longer
have the authorization to access, such
as terminated employees, or employees
whose roles have changed, are
accounted for, and restricted
accordingly
Monitoring access
patterns in real-time to
detect data leakage and
unauthorized transactions
Technical To ensure any abnormal access patterns
and behaviors are detected quickly and
resolved timely
Archiving external data
and encrypting databases
as well as backups
Technical To ensure all incoming and outgoing
data points are accounted for, and only
accessible by the authorized database
and system administrators, and third
parties, such as vendors and partners
Training database and
system administrators on
risk mitigation
Administrative Regular training will ensure compliance
with current federal regulations and
equip database and system
administrators with the knowledge to
identify and mitigate threats including
those from within such as social
engineering, shoulder surfing, phishing,
and collusion, among others
Enforcing database
management best
practices
Administrative
and Technical
To ensure best coding practices are
followed thus prevent Structured Query
Language (SQL) injection, brute-force,
unauthorized privilege escalation, and
exploitation of unpatched database
vulnerabilities
Implementing a strict
firewall ruleset
Technical To ensure only authorized traffic to the
database system, and easily identify any
attempts to exfiltrate or circumvent
access to the database through a
backdoor
(table continues)
Removing unneeded
services to reduce the
attack surface Technical
To ensure only the services needed are
running; therefore, reducing the
chances of attackers using irrelevant
services as a hook to reach into the
Solution Classification Purpose
operating system (OS) layer which may
lead to greater system compromise
Transition and Summary
The GST by Von Bertalanffy demonstrates the impact of interdependent elements
of people, processes, and technology working together in organizations to secure
organizational assets rather than each element working in isolation to achieve the same.
The GST is applicable to both small and large-scale organizations and focuses on
interdependent objects working together in a complex system while considering the
impact of external factors on the target system. This theory suits well research related to
exploring and describing the impact data security management strategies have on the
prevention of data breaches by malicious insiders.
Within this section, I discussed the topic of data security management strategies
and the impact of insider threats on this paradigm. By leveraging the GST as the lens for
my study, it allowed me to explore data security management strategies and the impact on
organizations. The review of the literature centered on explanations of data security
management, insider threats, insider threat attack schemes, the impact of data breaches,
and data security management technical and administrative strategies.
Based on the literature, there were no areas of discourse, contention, or divergent
perspectives. The literature reviewed identified the need for the improvement of insider
threat detection, or better yet, the prevention of data breaches caused by a malicious
insider altogether. The articles acknowledge that we, humans, are the weakest link in the
information security chain. I discovered from the reviewed literature that trust is a
standard theme across all the articles and plays a significant role in any IT enterprise,
whether small or large and private or government. The next section, Section 2, discusses
further areas of my research study, including the role of the researcher, participants,
research methodology, and design I chose for this study, population, and sampling, as
well as ethical research. Also, this section presents data collection, organization, and
analysis strategies, and addresses the topics of reliability and validity.
Section 2: The Project
In this section, I will provide information on the role of the researcher, potential
participants, the criteria for selection of participants, population sampling, and research
methodology. Also, in this section, I will address ethical subjects relating to my study and
steps I may take to alleviate such factors. Last, I will describe the data collection
instruments, data collection approach, data organization techniques, and data analysis, as
well as explain issues of reliability and validity in the context of this study. I will then
provide a transition and summary, leading to the final phase of my doctoral study.
Purpose Statement
The purpose of this qualitative multiple case study is to explore the data security
management strategies that database and system administrators use to prevent data
breaches by malicious insiders in small-scale IT government contracting agencies. The
targeted population was database and system administrators of three small-scale IT
government contracting agencies along the northeast region of the United States that have
data security management strategies. The implication for positive social change is that by
reducing data breaches, the unauthorized disclosure of consumers’ sensitive information
may subside, thereby preventing cases of identity theft and securing and preserving
business secrets and reputation, respectively.
Role of the Researcher
The researcher was the primary data collection instrument based on the nature of
qualitative research (Yin, 1981). In my primary role, as the sole researcher and primary
data collection instrument in this research study, I designed and conducted the study,
collected, organized data, as well as analyzed and presented the findings in an unbiased
manner. As a human, it was impossible to remove all bias; however, I did the best I can to
mitigate bias during the data collection process of my study. During the data collection
phase of my study, I leveraged an interview protocol (see Appendix A) and concluded the
interviews once data saturation was reached. Other data collection instruments used in
this study included semi structured interviews with open-ended questions either in-person
or via a remote communication medium such as Skype for Business or Google Hangouts,
any documentation furnished by participants, audio recordings, field notes including
observations, and transcripts from the interviews. The open-ended interview questions
were reviewed by my committee and peers to ensure the questions were free from bias.
As suggested by Leedy and Ormrod (2015), qualitative researchers should display
comprehensiveness, poise, and equality when analyzing and interpreting collected data. I
ensured data collected from my participants were comprehensive, poise, and ensured
equality when analyzing and interpreting research data by using the same data collection
instruments across all my participants. Using the same data collection instruments
ensured uniformity, equality, and would minimize bias.
Securing and working with data has always been a passion of mine; hence, I
entered the database and security engineering fields. Through my profession as a database
administrator with over 15 years of experience working in the field of study, ensuring
only authorized personnel to have access to data is apriority. My role over the years has
been that of more of database architecting, development, and operations, versus database
security management; hence, I consider myself to be unbiased and proactively sought to
alleviate any form of bias to the data collected was not skewed or tainted. The selection
of the topic and use of a multiple case study research design were selected based on my
interest to learn more and gain a wealth of understanding about the problem. From an
ethical standpoint, I ensured neither the target participants are from places I have
previously worked, nor do I know the participants professionally or personally. My
relationship to the geographical location of the study was that I worked in the region.
I reviewed the Belmont Report provided by the United States Department of
Health and Human Services. While conducting research, the Belmont Report serves as
ethical guidelines and principles for protecting research study participants (U.S.
Department of Health & Human Services, 1979). As a researcher, I treated all participants
ethically and with respect, and ensured risks are minimized. I have also completed the
Protecting Human Research Participants training offered by the National Institutes of
Health (NIH) Office of Extramural Research (Certification Number: 2275855) and have
enclosed my certificate of completion (see Appendix B). I ensured that all participants
were made aware that their names were kept confidential. I was sure to keep all interview
interactions confidential to maintain and protect interviewees’ identities and uphold
confidentiality. I followed the principles outlined in the Belmont Report.
I avoided bias in this doctoral study by making sure I did not inject any personal
values, subjectivity, and predispositions. Roulston and Shelton (2015) described bias as
any distortion or manipulation of data collected that threatens the credibility of research
either unintentionally or hidden from the researcher. Also, I recorded all the interviews
with the participants, transcribed the interview data collected, and performed member
checking. Member checking ensured that the data collected was accurate and reflected an
accurate representation of the participants and was free from bias. The integrity of the
data collected was maintained, if not enhanced, by using member checking.
Additionally, I was sure to avoid bias when selecting participants by ensuring they
were representative of the population. For this study, I used the GST as the conceptual
framework. Per Rule and John (2015), conceptual frameworks that will help with
navigating relationships between theories and case studies will be needed.
For this multiple case study, I used a maximum variation (also called
heterogeneous) purposive sampling technique, and out of the population interviewed two
database administrators and two system administrators from three different participant
organizations either in-person or via a remote communication medium such as Skype for
Business or Google Hangouts. A heterogeneous purposive sampling technique was
chosen because I wanted to capture a wide range of perspectives and experiences around
my research topic; therefore, gaining deeper insight and enriching my study. I followed a
semistructured interview approach either in-person or via a remote communication
medium such as Skype for Business or Google Hangouts and documented field notes and
observations during the interviews with participants. The interview questions were
aligned with the specific research topic, and I used level 2 questions. Yin (2014)
suggested the use of Level 2 questions, to ensure relevance to the research topic, which
are questions asked of the individual case. The open-ended type of questions allowed me
to ask transitional or follow-up type questions as well. Before finalizing the data
gathered, I presented the data collected to my committee and peers for review and
feedback.
Participants
For this study, participant selection will be conducted using the heterogeneous
purposive sampling technique. Per Suen, Huang, and Lee (2014), heterogeneous
purposive sampling involves the use of specific criteria to select elements from a
population and based on the purpose of the study. From three organizations located in the
northeastern region of the United States, I will pick participants for my study based on the
following criteria: knowledge and experience, years of service at the target organization,
and have implemented a data security management strategy. I will choose participants
based on their knowledge to assist with my research study. The determination of their
knowledge preference will be based on the systems they have worked with and their years
of experience. Peticca-Harris, deGama, and Elias (2016) suggested a dynamic, nonlinear
process of gaining access broken up into four elements: study design and planning,
identifying informants, contacting informants, and interacting with informants during
data collection, which is what I plan to achieve in my study.
I will contact the gatekeeper of each organization and discuss the purpose of the
research and the data collection process to ensure there are no company policy violations.
Next, I will communicate the research purpose, and data collection process, and then
provide each gatekeeper the participant screening questionnaires to distribute to potential
candidates in the solicitation process. The questionnaire will have content to gather
participant eligibility information, knowledge, experience, and use of data security
management strategies. The questionnaire will contain the following:
1. What is your current role and title?
2. How many years of database administration or system administration do you
currently possess?
3. How long ago have you implemented a data security management strategy?
4. How many years of experience do you have in this type of role?
5. How many years have you worked at this firm?
After identifying potential participants, I obtained the contact information of each
potential participant identified. Next, based on the participant selection criteria, I selected
my study participants: two database administrators and two system administrators. From
each organization, two database administrators and two system administrators were
selected, as a result, data saturation may be reached within each participant organization.
Next, I contacted each potential participant and provided an informed consent along with
an invitation to participate letter. The informed consent process informs the potential
participants of voluntary participation, disclosure, and discuss confidentiality.
After choosing the participants, I worked with the gatekeepers to obtain the emails
of my participants to set up interviews with each of them onsite, at a meeting space
offsite, or via a remote communication medium such as Skype for Business or Google
Hangouts. I worked to build trust and establish a good rapport with the gatekeepers and
participants. Building trust and a good rapport was a high priority. I communicated to the
participants the importance of the research and assured them their information would
remain confidential and solely for the study. I also informed the participants that the data
collected would be retained for five years.
I emailed the participants and briefed them about the interview process, including
the use of a recording device, and the creation of a transcript for review, estimated the
duration of the interview, among others, before the interview. Prior to the interview, I
enhanced the comfort level of my participants and built trust by asking each participant to
sign an agreement document that would indicate their role and responsibilities within the
organization.
Research Method and Design
This research study examined the lack of data security management strategies in
use by database and system administrators to prevent data breaches by malicious insiders.
The research method I chose for my study is the qualitative research methodology, and
the research design is a multiple case study. The qualitative research method provides me
with a deeper understanding of how database administrators and system administrators
use data security management strategies to prevent data breaches by malicious insiders.
Also, I ensured the research methodology and design I selected are in alignment with the
research question for my study.
The research question influences and shapes the research method and design of
the study. The type and scope of data collected, as well as the technique used for the
collection of data, was also relative to the research question. Therefore, establishing a
recursive relationship between research design and data collection sources. Additional
themes in the study were derivative of the nature of the information collected from each
participant. At the same time, synthesizing the data collected provided a full picture of the
research question. To reach the point where a deeper understanding of the research
question was answerable, a methodological triangulation of the various sources of data:
questionnaire, semistructured in-person interviews, and company documents, was likely,
which in turn yielded emergent themes among participants. As described by Yin (2014),
triangulation is the convergence of data collected from a variety of sources, to determine
the consistency of a finding. Triangulation ensures that the findings of the case study
have been supported by more than a sole source of evidence. Case studies typically solicit
level 2 questions, which are questions asked for individual cases, as suggested by Yin
(2014). Responses to such questions unraveled a better understanding of the phenomenon
under exploration.
It is vital for researchers using a case study research design not to lose sight of the
sequence of events due to the individual questions and answers asked of participants. In a
case study, the findings of the study are based on the entire organization and not the
participants. For instance, in a scenario where a case study is about an organization,
interviewing individuals, and collecting data on how and why the organization works, as
well as retrieving personnel policies, and organizational outcomes yield an enriched data
collection set.
Method
After considering the quantitative, qualitative, and mixed-method research
approaches, the research method I chose for my study is the qualitative research
methodology. As Kozleski (2017) suggested, one needs to use the qualitative method to
help gather information and obtain an understanding of human behavior and perspectives.
I chose a qualitative method because the intent of the study is to explore cases to gain a
deeper insight into data security management strategies that database administrators and
system administrators use to prevent data breaches. When there is a lack of substantive
information on a phenomenon, to gain a deep and rich understanding, researchers prefer
to use qualitative research (Houghton et al., 2015). Palinkas et al. (2015) stated the level
of depth of information collected theoretically helps to achieve data saturation in
qualitative research studies. The landscape of data security management and malicious
insiders continue to change and thus presents new challenges to organizations; hence, to
enhance my understanding and gather data based on experiences and knowledge of
database and system administrators on data security management strategies they use to
secure data from malicious insiders, I chose to conduct my study using qualitative
research.
I did not choose the quantitative research approach as the intent of the study is not
to understand the relationships between variables, or to validate or invalidate hypotheses.
Morgan (2015) found that in studies where researchers need to examine variable
relationships and test hypotheses, they use the quantitative research methodology. Yin
(2014) suggested quantitative research data is quantified for statistical analysis through
the evaluation of relationships between variables. Researchers use the quantitative
research approach to test hypotheses and examine relationships. In my study, I do not
intend to explore relationships or test hypotheses; hence, the quantitative method was not
appropriate for my research study. In a study conducted by Barnham (2015), he
concluded that researchers using the quantitative research approach extrapolate meanings
of research questions using the same approach for each participant as they assume their
study participants will answer questions in the same manner. However, the intent of my
study is to gain a deep understanding of the data collected from study participants based
on their perspectives.
Even though the mixed-method approach enhances the strengths and minimizes
the weaknesses of the other mono-methods, I did not choose to use mixed-method for my
study because it contains elements of both qualitative and quantitative methods, which
may result in resource constraints, such as time, effort, and is costly. The mixed-method
research approach offers researchers a variety of benefits, including triangulation,
minimizing bias, increasing validity, enhancing the strengths, and decreasing the
weaknesses of the mono-methods of quantitative and qualitative methodologies. After a
review of current research, McCusker and Gunaydin (2015) offered the opinion that a
researcher needs to weigh the cost involved in researching to identify the most efficient
method. Cost and time to complete a mixed-method research study are the reasons some
researchers do not pursue a mixed-method study as researchers need to assemble and
coordinate expertise across both quantitative and qualitative methodologies, as well as the
associated demands to publish the research study findings (Turner, Cardinal, & Burton,
2017). Additionally, my research does not warrant a combination of qualitative and
quantitative research methods. Therefore, it was not appropriate for my doctoral study.
The quantitative aspect of mixed methods requires the formulation and testing of
hypotheses (Green et al., 2015). However, the intent of my study is to gain a deeper
understanding of the research question using semi structured interviews with open-ended
questions; therefore, I did not choose the mixed-method research approach.
Research Design
For my research study, I chose the multiple case study qualitative research design
to address the research question adequately. Miller and Coutts (2018) concluded that the
qualitative multiple case study research design elucidates a variety of ways to answer
how and why questions. The multiple case study research design supports the exploration
of a phenomenon through various evidence sources and provides a rich description of
single or multiple cases within a real-life context (Cousins & Bourgeois, 2014). Multiple
case study research design is an ideal approach for identifying common patterns based on
historical details (Di Mauro, Fratocchi, Orzes, & Sartor, 2018). Researchers use evidence
sources such as documents, observations, artifacts, and interviews in the case study
research design. The purpose of semi structured interviews, as well as open-ended
questions, would serve me better gain a deeper understanding of the information collected
for my study. Fernández and Wagner (2016) asserted the use of a case study research
design enriches the exploration of phenomena in their natural context. Case study
research design reflects the personal experience of the research study participants and
guarantees success in understanding a situation in great depth for a defined timeframe
(Pacho, 2015). In using the multiple case study research design, interviewing of
participants, organizational documentation collection, and observation, and field notes
were among the crucial sources of data.
Researchers use the phenomenological approach to research people who have
experienced a phenomenon and how they lived through it (Sauro, 2015). Sloan and Bowe
(2015) suggested that the sample sizes of participants are small, and thus allows the
researcher to become deeply involved in the data and phenomenon. Becoming deeply
involved in the data is a facet of case study research designs as well; however, the sample
size may not be large enough to yield the intended information to answer the research
question. Researchers use phenomenological research to gain a phenomenological
understanding of the perspectives and experiences of their sample population, rather than
an explanation of a phenomenon from participants’ experiences (Woodgate et al., 2017);
therefore, a phenomenological research design will not be appropriate for my study as my
intent is to explore the research question and gain a deep understanding from a larger
sample population.
Hallett and Barber (2014) suggested that researchers use the ethnography research
design to study a specific culture or group over a period without the use of interviews and
observations, which is the intent of this study. Researchers use ethnography research
design to observe and understand subjects of their research study for knowledge
production, leading to political intervention or nonintervention into the lives of the
study’s subjects (Reed, 2016). The intent of my study was to explore the strategies used
by my participants and not to intervene in their lives. After an extensive review of current
research, Astuti (2017) offered the opinion that ethnography research design requires
researchers to let go of the participatory experience and turn against it. The intent of my
study was neither to participate in the organizations of my participants or turn against
data collected from them; therefore, the ethnography research design was not appropriate
for my study.
Another qualitative research design considered was narrative. Per Singh, Corner,
and Pavlovich (2015), researchers use this research design to gain the meaning of life
through stories. The focus of my study was not to gain meaning of life but to explore
strategies in use by my participants; hence, I chose not to use narrative research design.
The narrative research design involves researchers gathering stories from participants that
may not have been analyzed, and an explanation of the data collected can change (Lewis,
2015). Data analysis was a vital component of my study as the data collected underwent
coding and categorization into themes to enhance my understanding of the data collected
to answer the research question consistently without changing. Hossain (2017) described
that narrative research designs focus on what information is disclosed, and not how it is
disclosed. I intended to document how participants answer the interview questions, as
well as create field notes and record the interviews; therefore, the narrative research
design was not appropriate for my study.
Per participant organization, data saturation was reachable when all participants
responded to specific questions with the same answer. Each participant’s case is worked
vigorously to obtain a deep understanding of the data security management strategies in
use, no matter how long it takes (Stake, 2006). Fusch and Ness (2015) suggested that
when no additional information, themes, codes are uncoverable, and the findings of the
research duplicatable by other researchers, data saturation has occurred. Data saturation is
inadequate when researchers use just one facet of reaching data saturation, such as the
researcher hearing it all (Morse, 2015). Instead, saturation should be determined by a
multitude of factors, including data collection, and an in-depth understanding of the topic
of study, among others. Harvey (2015) recommended that member-checking is usable in
qualitative research methodology to verify data collection accuracy and completion from
participants. Therefore, to confirm data saturation in my research study, member
checking with participants was one of the characteristics I used to ensure no additional
information was uncoverable.
Population and Sampling
The population of my study includes database administrators and system
administrators of three small-scale government contracting IT organizations in the
northeastern region of the United States. The population for the study has knowledge and
experience around data security management strategies. I chose two database
administrators and two system administrators from three organizations using the
heterogeneous purposive sampling approach based on defined criteria.
Cati, Kethuda, and Bilgin (2016) asserted the specific criteria defined must be
attainable by the sample to become a research population. Therefore, all 12 participants
met the criteria of a five-year minimum work experience and knowledge of data security
management strategies and worked at their organizations for a minimum of five years.
Determining the sample size needed to reach data saturation for a case study is known to
be a difficult determination to make (Boddy, 2016). The number of participants, the
collection of data and related documents, and ensuring triangulation, are strategies to help
ensure data saturation is attained for my study on small-scale organizations. The United
States Small Business Administration (SBA) describes a small-scale firm as one that has
a minimum of 500 employees (SBA, 2012). The SBA considers and categorizes small
businesses according to its chart of size standards, which reflects the size of small
businesses ranging anywhere from 500 to 1,500 employees (SBA, 2016). Also, Fugard
and Potts (2015) suggested the use of thematic analysis to analyze qualitative data
collected in similar research studies prior to mine, and how the sample size affects those
research studies. Considering the key points stated in the above paragraph may ensure
attaining data saturation.
The site and setting of the interview may impact the quality of the interview and
the data collection. I coordinated to set up interviews with each participant via the
gatekeeper of each organization. As suggested by Pryce, Tweed, Hilton, and Priest
(2017), I sent written and verbal information about my research study and made my
participants aware their responses would be confidential, and they could withdraw at any
time prior to chief academic officer (CAO) approval. I planned to interview each
participant in-person or via a remote communication medium such as Skype for Business
or Google Hangouts. I estimated that my interviews would take about 30 minutes to 1
hour. If it took longer, I was sure to be attentive to the participants' comfort and would
take a break. Kasim and Al-Gahuri (2015) asserted building trust and maintaining good
rapport with participants is key to data collection and the research study. I reminded my
participants before the interview about their confidentiality and preservation of their
privacy, as one of many approaches I used to build trust, comfort level, and establish a
good relationship. Another approach I used for ensuring quality data was collected during
the interviews was by improving the reliability of interview instruments before using
them by seeking feedback from my research committee (Richardson et al., 2017). I
planned to hold the interviews in private in a conference room or a quiet enclosed office
space to minimize distractions.
Ethical Research
Ethics in research is an important aspect. The need to ensure ethical behavior and
activities is to protect and preserve the privacy and confidentiality of the research
participants. For my qualitative research study, I conducted the research ethically and
honestly to minimize harm to all my participants. By email, I provided all my participants
with a form that contains information about their consent to my research study. Obtaining
informed consent from my participants attempts to secure their ethical rights (Biros,
2018). Achieving consensus to proceed with my research study did not only pertain to
enrolling participants, but also conveyed information about rights as human subjects to
uphold, protect, and respect the rights of my participants. In addition, attaining consensus
involved the communication of the research question under study, the methodology in
use, as well as the benefits and harms to the participants of my study (Zhang, 2017). The
consent process also informed participants of voluntary research study participation,
voluntary disclosure, and discuss privacy and confidentiality of research artifacts.
I ensured to communicate in the consent form the terms and conditions for
participating in the study and provided details on the option to opt-out during the initial
phase of the research study. Nair and Ibrahim (2015) suggested that considerations made
to ensure confidentiality of participants are essential to ensuring ethical safeguards in the
consent form. As the researcher, I protected the confidentiality of the participants in the
research study.
I informed participants both verbally and in writing of the option to withdraw at
any time prior to chief academic officer (CAO) approval. Although Hershey and Hession
(2017) suggested that demands, discomforts, or difficulties associated with my study may
influence participants to withdraw, I ensured participants were not coerced or obligated in
any way to prevent them from withdrawing. Also, I did not offer any monetary incentives
to participants for participating in my research study. A copy of the study results would
be made available to anyone who requests a copy.
The data collected from this multiple case study would be stored securely for five
years in a private safe box that would be only accessible by me. Preserving the
confidentiality and privacy of my participants’ data builds trust and establishes a good
rapport (Hoyland, Hollund, & Olsen, 2015). I ensured I deidentified participants and their
organizations; I used pseudonyms to protect their identity, as well as preserve their
privacy and confidentiality (Dessi & Sebastian, 2017). I will destroy the data collected by
following procedures set forth for the destruction of data obtained after five years.
Data Collection
The data collection methods I used in the study included 12 open-ended questions,
semistructured in-person interviews, organizational documents, including archival
records, and direct observations. In Appendix C, I discuss in more detail the direct
observation protocol. Based on the policies and procedures governing a participant
organization, I obtained publicly available documents through the United States
Department of Defense (DOD) Chief of Information Office and the NIST websites. As
suggested by Yin (2014), the interview, as the mode of collecting research data, via
verbal communication with each participant of my study, is conversational, yet guided by
the research purpose. As noted by Scheibe, Reichelt, Bellmann, and Kirch (2015), the
relaxed nature of the conversation fosters participants to respond to interview questions
freely. A consent form was sent to each participant prior to conducting the interviews to
obtain agreement from each participant. The consent form included information
pertaining to the use of an audio recording device.
Instruments
I served as the primary data collection instrument as the researcher of this
multiple case study. Neuman (2014) asserted the researcher is the ideal
datagathering device as the researcher can pursue emerging dimensions of a study
that is beyond the scope of other instruments designed beforehand. Other data
collection instruments for the research study include semistructured interviews,
direct observations, documentation, and archival records analysis. Also, I made the
participants aware prior to conducting the interview that I would be recording the
interview.
The semistructured interviews were performed using an interview protocol,
which can be found in Appendix A. Dikko (2016) suggested an interview protocol
serves as rules and guidelines by which researchers go by to conduct interviews.
Following an interview, protocol facilitates the interview conversations and ensure
consistency by helping me to ask participants the same questions (Castillo-
Montoya, 2016). The benefit of recording the interview ensures that if the
researcher forgets any keynotes, the researcher can go back to the recording to fill
them in. Additional cues could also be drawn from participant gestures or tone that
may contribute to the research study.
I used methodological triangulation and performed member checking with each
interview participant separately. After review and agreement from the participants that
the information collected is accurate and reflects their views, I imported the data collected
into a software program called NVivo. As suggested by Houghton et al. (2015), this
software helps researchers to break down the data collected into manageable pieces. I also
informed the participants about the use of the NVivo software and storage of the data
following the Walden University research data retention guidelines.
Data Collection Technique
Data collection commenced once I obtained Walden University’s Institutional
Review Board (IRB) approval. I conducted this study under Walden IRB approval
number 11-13-18-0604496. Semistructured interview questions were used for my
interviews, and interactions during the interview process were recorded using the
Audacity software. Prior to the interview, I emailed the consent forms to each participant
and did not follow a paper-based approach. On the day of the interview, I arrived at the
participant’s site or logged in to the remote software early and tested the Audacity
software to verify it can capture the audio within the interview setting to ensure proper
functionality and quality. I conducted interviews for each participant onsite at their
respective organizations or via a remote communication medium such as Skype for
Business or Google Hangouts. After I collected data from each participant of my study, I
transcribed the data.
As part of the data collection process, I took direct observational field notes.
Stuckey et al. (2014) suggested that researchers use direct observations to help confirm or
challenge interview data. I used the interview notes to inform the discussions during
observations. If deviations were noted between the interview notes and direct
observation, I asked the participant for clarification. After transcription of each interview
and direct observation, I conducted member checking with each participant. Santos,
Silva, and Magalhaes (2017) concluded that member checking ensures the accuracy and
consistency of the transcription of the interview. The outcome of the member checking
processing is the feedback obtained from participants (Liao & Hitchcock, 2018).
Feedback from the member checking process enhances the quality of the interview data
collected. Improving the quality of data collected from interviews through member
checking enhanced the trustworthiness of my research study results.
As part of the organizational documents and archival records collection, if any, I
worked with the organizational point of contact. Kasim and Al-Gahuri (2015) asserted
lack of knowledge and understanding of participants could have an adverse impact on a
research study. Therefore, I ensured that there a clear understanding and expectation of
the need for the documents. I requested electronic copies of the data via email and
analyzed each resource per participant organization entirely offsite at my home office
personally.
Data Organization Techniques
After the interviews, I transcribed the audio recordings into a format that is
accessible and readable, such as Microsoft Word. I aimed to complete the transcription
process within a week of the final participant interview. Bannon (2015) concluded
researchers should develop a solution that could help them to diagnose how serious the
issue of missing data is within a specific dataset. Therefore, I ensured during the
interview process that I accounted for any questions a participant was unable to answer
due to nondisclosure or sensitivity reasons. Using this check, I could assess the level of
impact of the missing data to my study. I performed an analysis of the data collected from
each participant, and then merged the data obtained along with the existing data collected
from the prior participants, and then analyzed further. I leveraged Microsoft Excel to
maintain a log of my activities and to help me stay focused and organized. Any reports
generated after the study would be shared with participants of each respective
organization. I encrypted the removable media holding the information gathered and
stored it in a secure location in my home for safekeeping. I tried my best to limit the
number of hard copy artifacts. However, I labeled any hardcopy artifacts clearly and
securely stored them in a similar fashion as the data saved to the encrypted, removal
media. Should any of the hardcopy data be needed in electronic format, I would scan
them.
Additionally, transcripts captured, member checking write-ups, and notes, as well
as logs from direct observation, underwent conversion into electronic format to be
included in the data analysis activities. Names of participants and organizations, as well
as other identifying information, were masked to ensure privacy and confidentiality.
Gustarini, Wac, and Dey (2015) concluded that the retrieval of rich data is enhanced if
data collection is anonymous. The data was then be loaded into the NVivo qualitative
data analysis (QDA) software to perform thematic coding, as well as further analysis.
NVivo supports researchers by reducing manual tasks and helps to discover tendencies
and recognize themes (Adetoro-Adewunmi & Damilola-Ajayi, 2016). At the end of the
data collection and analysis process, I will retain all data stored, both soft and hard
copies, for five years before destroying them. I purged the data stored on the removable
drive and shred hard copy documents. Electronic copies of organizational documents
were stored on a removable storage media. The electronic data was then be imported into
NVivo for thematic coding and analysis.
Data Analysis Technique
Performing an iterative and continuous analysis of the data collected improved the
quality of my study in general, leading to more reliable findings to answer my research
question. I used a thematic coding and analysis technique for my research study and
NVivo, a qualitative data analysis (QDA) tool, to assist with this activity. Scheibe et al.
(2015) suggested that such software may assist in the organization and analysis of
interview data, but the success of the use of the software as a research tool depends on
me, the primary research instrument. Also, the use of computer software to assist with
data analysis is crucial as qualitative data analysis requires time, is extensive, and
meticulous (Yakut Cayir & Saritas, 2017). According to Robins and Eisen (2017), NVivo
software is essential for the successful completion of research projects involving a large
volume of data to be analyzed within an intense timeframe. Using NVivo software helped
me to save time and effort, especially with the research design I have chosen.
From the thematic coding and analysis activity, themes were identified in a
horizontal cross-section fashion of my participants. The thematic coding and analysis
process involved identifying, analyzing, and reporting patterns I found in the data
collected. Maintaining consistency in coding ensures minimization of challenges with
data management, organization, and analysis (Vaughn & Turner, 2015). I created and
used labels, based on a determined naming convention, to properly isolate each theme
and information relating to that specific theme. As part of the analysis process, I also
leveraged the chosen conceptual framework, GST, to serve as an additional viewpoint by
which I analyzed the data collected for the research study.
Reliability and Validity
It is vital for qualitative research studies to possess the elements of authenticity,
which is reliability and validity (Noble & Smith, 2015). Researchers ensure reliability and
validity in qualitative studies using a variety of techniques, including the review of post-
interview transcripts, member checking, and triangulation, among other methods and
practices. Florczak (2017) asserted that if one wants to know about the meaning or gain
an in-depth understanding of a certain life event or phenomenon, one will choose a
qualitative approach. Researchers use the qualitative approach to help answer difficult
‘what’ questions, or when they need a new perspective about a phenomenon. Measuring
the quality and trustworthiness of a qualitative study is achievable using four criteria:
credibility, transferability, dependability, and confirmability (Morse, 2015). The
mechanisms I leveraged to establish credibility, transferability, dependability, and
confirmability follow.
Dependability
The research quality of dependability refers to the extent to which a measure,
procedure, or instrument produces the same results when used repeatedly (Lili-Anne &
Eeva-Mari, 2015). In my study, ensuring I used the same interview instruments across all
participants shows consistency. Lawrence (2015) suggested the crux of reliability in
qualitative studies resides in uniformity. Yielding consistency provided stability during
the aggregation and measurement of the interview results, thus ensuring reliability.
Cypress (2017) asserted researchers need to be proactive and take responsibility to ensure
the reliability of their research studies. Therefore, to be proactive and take responsibility
to ensure reliability in my research study, I used strategies congruent with the qualitative
methodology to ensure the reliability and trustworthiness of the study. These strategies
included the use of interview and direct observation protocols, conducting member
checking, and ensuring transparency throughout the research process, as well as
providing a clear description of the data collection and analysis instruments, as well as
techniques. Dependability of my research findings was confirmed after performing
member checking to ensure my interpretations of the data collected were an accurate
depiction of the views of my participants. Another approach I used to ensure
dependability is direct observations. Field notes captured during the direct observation
activities were used in conjunction with organizational documents and triangulated with
the interview data.
Credibility
Credibility establishes the feasibility of the research study results from the study
participants’ perspective. Noble and Smith (2015) asserted that clearly and accurately
reflecting the data collected, as well as accounting for bias that may have influenced
research findings, ensures credibility. One area of ensuring credibility is accounting for
bias that may influence my research. Nair (2018) suggested researchers need to be
cognizant of areas where bias is injected, including data supplementation, theory
confirmation, and model simplification. I ascertained bias was not introduced when
collecting, transcribing, analyzing, and reporting the research study results.
In addition, explaining the data collection instruments and processes, as well as
ensuring consistency with each participant during the entire study, helped to establish
credibility. I conducted member checking after interviewing with participants to validate
the accuracy of data collected. As part of the member checking process, I returned the
data collected to participants to check for accuracy and resonance with their experiences
(Birt, Scott, Cavers, Campbell, & Walter, 2016). Performing member checking enhanced
the level of trust of the data collected, and hence, the quality of the research study results.
Also, the conduction of direct observation offered an additional facet that I used for the
triangulation of data I collected from the study participants. After collecting data from
each participant within each organization, as well as across organizations, I ensured data
saturation is reached. Transferability
Researchers must ensure enough information has been provided for other
researchers to transfer research findings to ensure transferability. Researchers must apply
techniques to allow for the generalization or transferability of the results beyond the
specific study (Weis & Willems, 2017). With the challenge of invalidity caused by the
narrowing of the scope of the qualitative phase in mind, I ensured the methods and
practices I used for conducting the research study remain intact and not tainted. Marshall
and Rossman (2016) stated that the burden of demonstrating research study findings
apply to another context or are transferable would be made by another researcher and not
the original researcher of the study. The interview protocol, direct observation protocol
(see Appendix C), other research study materials, as well as results from my study, would
be retained for five years. Connelly (2016) suggested researchers support transferability
in their study with a rich, detailed description of the research study context, location, and
participants. Retaining the artifacts provides readiness while ensuring integrity, should
there be a need for auditing or reuse of the research artifacts and data for further analysis
or studies.
Confirmability
The quality of confirmability in qualitative research is the degree to which other
researchers can confirm the findings of a research study (Korstjens & Moser, 2018).
Confirmability ensures the research findings are strictly based on the data collected in the
research study, and not made up. Abdalla, Oliveira, Azevedo, and Gonzalez (2018)
emphasized the need to promote triangulation to reduce the influence and effects of the
researcher. I interviewed all the participants of the study as part of my strategy to enhance
confirmability. Interviewing all participants enhanced the quality of the data collected as
it included all participants' responses and organizational artifacts. Also, the data
collection consisted of audio, text, and interview transcripts, thus conforming to
qualitative approach requirements. I structured the interview questions in a manner that
spoke to the participants and drew valid responses. Kihn and Ihantola (2015) suggested
that researchers follow a systematic way of building upon prior research and drawing
valid responses from their study participants. Therefore, in this qualitative research study,
I sought validity by drawing valid responses from my participants; therefore, I ensured
the structure of my questionnaires and interview questions spoke to my participants.
Transition and Summary
In Section 2, I described my role as the researcher of this study, participants,
research method, research design, population and sampling, and the ethical research
aspects of this study. Additionally, details in this section included data collection
instruments, data collection techniques, data organization techniques, and data analysis.
This section also included discussions on ensuring reliability and validity for this study,
leading to the conclusion of this section of my study with a transition and summary
section.
The next section of this study, Section 3, includes a presentation of the findings
for my study, application to professional practice, and implications for social change.
Further discussions offer recommendations for action and recommendations for further
research. This section then concludes with discussions on reflections, and a conclusion.
Section 3: Application to Professional Practice and Implications for Change
The focus of this study was exploring data security management strategies that
have been implemented by organizations to prevent data breaches by malicious insiders.
In this section, I will showcase findings from data collection and data analysis, as well as
describe how this study may contribute to research in the field and society. Additionally, I
will address positive implications for social change. I will conclude with suggestions for
future work and reflect on the study.
Overview of Study
The purpose of this qualitative, multiple case study was to explore data security
strategies that database administrators and system administrators use for preventing data
breaches by malicious insiders. The data for this research study came from performing
semistructured interviews with database and system administrators, analyzing
organizational documentation, and conducting direct observation. The section begins with
a brief synopsis of why and how the study surrounding data management strategies was
conducted, and I then provide a summary of the study findings.
Presentation of the Findings
At the inception of this study, I sought to address the following research question:
What data security management strategies do database and system administrators use to
prevent data breaches caused by malicious insiders? The results of this study may be used
to help address the specific IT problem that some database and system administrators lack
data security management strategies to prevent data breaches by malicious insiders in
small-scale IT government contracting firms. In this section, I will present the findings
for my research study and present the four major themes that emerged after conducting
the study. I used methodological triangulation to analyze the following sources of data,
including semistructured interviews, direct observation of a training meeting,
organizational documents, procedures related to managing and strategizing data security.
I used follow-up member checking to enhance the methodological triangulation and to
validate the correct representation of the data. The four major themes that emerged from
data analysis were as follows: (a) enforcement of organizational security policy through
training, (b) use of multifaceted identity and access management techniques, (c) use of
security frameworks, and (d) use of strong technical control operations management
mechanisms. These themes illustrate potential strategies that could be used to secure data
from breaches by malicious insiders I small-scale government contracting organizations.
Theme 1: Enforcement of Organizational Security Policy through Training
One emergent theme from data analysis was the enforcement of organizational
security policy through training. According to Mann (2008), humans are targeted because
they are the weakest link in any security chain. The findings from the case studies showed
that organizational personnel is the most important asset in any organization and could be
the weakest link in the information security chain. The study shows that security training
of personnel could help improve employee security savviness, leading to an overall
enhanced security posture of an organization by minimizing the likelihood of data
breaches occurring. Based on the study findings, security training could be in a generic or
targeted format to ensure all employees comply with organizational policies and withhold
a certain organizational culture to maintain or enhance the security posture of that
organization.
Participants from the study noted that targeted security training is based on the
roles of personnel within an organization. Some targeted training sessions are facilitated
by vendors of the applications they use, and others take the form of an internal subject
matter expert (SME) training the other technical staff. Also, research study participants
noted that targeted training is sometimes conducted onsite, and on other occasions,
selected technical staff is sponsored for offsite training. For an organization to maintain a
culture of security, there needs to be, at a minimum, an annual requirement for all
employees to undergo some form of security training. In the case of government
contracting organizations, which is the case for this study, annual security compliance
training of organizational personnel is required as part of the organization strategy and
required by the government agency for which work is being performed.
Table 3
Frequency of First Major Theme
Participant Document Direct Observation
Major/Minor
Theme
Count References Count References Count References
Training 8 35 3 6 1 3
Note. Theme 1, enforcement of organizational security policy through training; n =
frequency.
Al eight interview participants from both organizations indicated the importance
of having security training built into the overall organizational strategy and culture for the
implementation of a firm data security management strategy to guard against data breach
by malicious insiders. The interviewees noted the importance of having a mechanism in
place to measure the effectiveness of security training offered. Training employees
creates awareness and educates on ways to avert techniques used by malicious insiders,
such as social engineering, tailgating to access restricted areas, and shoulder surfing,
among others. Company A P1 noted that “taking an annual training was an organizational
strategy,” and P4 from the same company added that “job-related training; Okta tool
training specifically; SMEs are trained by vendors.” The notes from both participants
aligned with a statement by Participant 1 from Company B, who noted that “we have an
annual required cybersecurity four-hour training and is mandatory, which issues a
certificate to the employees” as an organizational mechanism to ensure staff is compliant
with data security management protocols. Company A P4 in the direct observation
training session mentioned a targeted upcoming training session for an employee:
“employee A has the privilege of going to training and learning how to do this so he can
take over doing this going forward.” Company A P1 noted that “organizations should
reach out to external resources for best practice and training.” Company B P2
summarized the training needs by noting that training must be in these forms: “mandatory
training; targeted training for privileged employees, and general training for all users.”
Company A P1, P3, and P4, as well as Company B P2, and Company B P4, all reported
in their interviews, the need for organizations to train their personnel, especially
privileged and technical staff, to undergo more rigorous and frequent training sessions to
safeguard sensitive information from data breaches. Further, all eight interviewees
alluded to some form of annually required training to ensure compliance and educational
awareness to maintain organizational security culture.
The theme of enforcement of organizational security policy through training
aligns well with GST as the conceptual framework for this study because GST considers
factors within a system, an organization in this sense, that can shape the outcomes, or
organizational culture in this case, leading to an altered output from the system, which is
a reduction in the threat of malicious insiders causing data breach. Syynimaa (2017)
noted that the GST allows ICT practitioners to describe the enterprise and its components
and how the components within the enterprise system are controlled to execute a change
that can be managed. Caws (2015) explained how GST was and is still used to break
down partitions between entities that left each busy in its own existence, and how that
affects the synergy and outcome. Von Bertalanffy (1972) described how to be able to
determine what changed as the outcome of a system, and there is a need to look at the
system in the context of the history of the system. Reviewing the nature of a system prior
to asserting factors that may influence that system provides a way to assess the cause of
change and the level of impact the change had on the system.
In alignment with the GST, the type of training required to affect a security-aware
employee culture is known by the principle key players who set the organizational
training policy; therefore, training programs that are not relevant to the organization are
not provided to employees. For instance, an IT service-based organization that does not
deal with health data may not train their employees on securing data according to HIPAA
privacy laws. Therefore, the emerged theme of enforcement of organization security
through training aligns with the GST.
The literature supports this theme and is pertinent to the emerged theme of my
study that enforcing organizational security through training, especially mandatory
training, can enhance the security posture via the improvement of the organizational
culture. Company A P3 and P4, and all participants of Company B discussed the impact
organizational mandated training has had on their respective organizations.
Methodological triangulation was achieved, as two of the collected organizational
documents, as well as the direct observation on training, supported this theme. For
example, according to the AC-2 control of the NIST Special Publication (SP) 800-53,
special training is required for some types of information systems. With the adoption of
this policy by organizations, technical personnel would gain knowledge of the appropriate
way of handling and managing accounts that access special systems to better protect them
from tampering, which could lead to a data breach. In my direct observation of a training
session, I obtained insight into training sessions planned for personnel that would be
administering a yet-to-be-introduced configuration management database (CMDB) that
would help to manage information about enterprise-wide hardware and software assets.
Also, scholarly literature coincided with the methodological triangulation to shed light on
the effect of training, both general and targeted, on organizational culture that inhibits
data breaches.
Revamping the security culture of an organization through security training
programs could be an effective measure to minimizing the likelihood of data breach
threats, and ultimately the retention of trust between government contractors and the
government agency they support. Aurigemma and Mattson (2017) asserted that
employees under the DoD umbrella are required to complete a meticulously tracked
mandatory information security training annually and that failure to comply with the
training requirements could result in a loss of access to DoD IT systems at a minimum.
The observation made by Aurigemma and Mattson in their research confirms the claim
made by Korpela (2015), who discussed that security training is valid preventative
controls to prevent social engineering, which is one of the mechanisms leveraged by
malicious insiders to gain unauthorized access to cause a data breach. The findings of
both works of literature align with participants’ reports. The literature and methodological
triangulation provided some validation of the impact of organization security training
programs on data breach prevention in small-scale government contracting organizations.
Aligning organizational training with organizational objectives should be
paramount in security training program offerings. Casey et al. (2016) suggested that
employee training is not only effective to enhance knowledge, but also to maintain
awareness of policy in place within an organization. One such scenario is to prevent data
contamination, which is the transfer of information a higher classification to a lower one.
The assertions by Casey et al. aligns with the conclusion drawn in a study by Saa,
Moscoso-Zea, Costales, and Lujan-Mora (2017) on the data security challenges
organizations encounter when transitioning to a cloud-based system. Saa et al. noted the
need for companies to educate their staff using training programs and campaigns about
data security risks and the necessary actions to mitigate those risks to prevent sensitive
corporate information from becoming compromised. The GST, therefore, explains why a
system could become more secure by infusing it with a change, such as training, to
change the outcome of that system, which is a reduction in the likelihood of a data breach
by malicious insiders occurring.
Theme 2: Use of Multifaceted Identity and Access Management Mechanisms
The use of multifaceted identify and access management mechanisms was another
theme that emerged from the data and is vital when implementing data security
management strategies to prevent data breaches by malicious insiders stemming from
relaxed access management mechanisms. Identity and access management mechanisms
come in a variety of shapes, along with a level of complexity. According to Kennedy and
Millard (2016), multifactor authentication is a more robust technique for maintaining the
security of sensitive data. The effective use of multifactor authentication could be a
combination of either two of three authentication mechanisms: something an employee
has, something an employee knows, or something an employee is. The first form of
authentication is generally in the form of physical devices such as a token, a proximity
card, or key fob, among others, that an employee swipes, touches, or inserts into a
physical reader to gain access to a location, a room, or a computer, among others. The
second form of authentication involves something an employee knows, including a
passphrase, a pin, a password, or a combination of the previously stated options. The third
form, also known as biometric authentication, comprises the use of a bodily part or
function, such as the veins in the palm, iris, retina, or fingerprint, among others. The
latter is usually frowned upon due to the invasiveness and the use of highly sensitive
personally identifiable information, which may not be stored or transmitted properly.
The higher the effectiveness of the strategy used for identity and access
management, the higher the chances of avoiding nonrepudiation, which is the term for an
individual claiming they were not the actor of a specific action. Finally, the theme of the
use of multifaceted identity and access management mechanisms requires the use of
multiple, or multi-factor authentication techniques to be effective for decreasing the
chances of successful attempts for attacks by malicious insiders, such as user
impersonation, privilege escalation, and fraud.
Table 4
Frequency of Second Major Theme
Participant Document Direct Observation
Major/Minor
Theme
Count References Count References Count References
Use of
multifaceted
identity and
access
management
mechanisms
8 116 3 6 1 3
Note. Theme 2, use of multifaceted identity and access management mechanisms; n =
frequency.
Three of the organizational documents collected, and the direct observation on
training, supported the theme of the use of multifaceted identity and access management
mechanisms, therefore achieving methodological triangulation. Based on my analysis of
the NIST Special Publication (SP) 800-53, an organizational document collected from
Company A, I noted that AC-2(8) control discusses trust relationships and mechanisms,
which are established with appropriate authorities, such a certificate authority, or CA, to
validate related authorizations and user privileges. By leveraging this type of policy,
organizations are endowed with a sense of validity due to the endorsement provided by a
trusted third party, thus, providing a form of checks and balances in the user account
provisioning process. It then becomes more challenging for a malicious insider to create a
token or access card on their own. Ensuring users are authenticated through a single
source was an in-depth topic during the direct observation training session. Scholarly
literature also coincided with the methodological triangulation to enhance the finding that
the use of multifaceted identity and access management mechanisms may be a data
security management strategy to prevent data breaches by malicious insiders.
All eight participants from both participant organizations indicated that the use of
multi-factor authentication and a variety of access management mechanisms, including
the use of roles, auditing, and strict access controls, are important strategies to discourage
malicious insider activity that could lead to a data breach. For instance, the use of a
multifaceted approach means the malicious insider will need to be sophisticated enough
to circumvent all the controls in place to reach the system containing the target data. For
instance, a malicious insider may attempt to escalate their privilege to access a system
outside of their role; however, with additional controls in place such as an access control
list or firewall could prevent or slow down the malicious insider. As part of effective data
security management strategies, the eight interviewees indicated that a layered approach,
including password management and enforcement, and privileged user access
management, reduces the probability of a malicious insider successfully carrying out a
data breach. Company A P1 discussed encryption of authentication tokens to systems,
and ensuring passwords are set to expire so that they can be updated regularly.
In some cases, in addition to role-based security, profile base security at the
application level is implemented to add another layer of protection is added. Company A
P3 noted that roles and extra built-in mechanisms “restricts access based on what kind of
role the user plays in the organization, depending on that we have profile settings, and we
only give a user those privileges, and only those resources will be seen by them.” As a
layered strategy, the administrative techniques of this strategy cannot be overlooked.
Company A P3 again stated that:
any requests need to be approved as far as access requests go. Anytime access is
required, a ticket is created, and the ticket goes through several approval layers,
and depending on the approvals on the business side, IT side, and manager of the
requester, then the ticket comes back to us, and we validate, and then after that we
provide access.
Having an audit trail of account provisioning can assist with making account management
audits easier, which is another essential activity some organizations conduct regularly to
ensure account provisioning is done according to organizational policy. Company A P4
noted further that the need to use department-based access management is key especially
in cases where specific groups of users need to access systems containing sensitive data.
From Company B, P1, P2, P3, and P4 indicated that measures are in place for
varying levels of access to the corporate network, such as the use of virtual private
networks for encrypted connections, and jumps as an added layer of identity and access
management mechanisms that an organization can leverage as part of their data security
management strategy. Company B P1 added that “there’s no way you can access our
system using another laptop, except using the government-provided laptops,” which
provides an added layer of security. Company B P3 confirmed that there are security
measures in place to prevent unauthorized access, role-based access, such as firewall
rules, and account lockout policies to prevent brute-force attacks: “if somebody tries to
randomly access or try to guess a log in and try to tamper, we will lock the account on the
third attempt, so the account is not accessible after that.” The basis of identity and access
management is the use of known information of users of the system to authenticate and
authorize their access to the system. Each users’ information and allowable method of
authentication are known. For instance, users cannot connect to the organizational
network or system using personal computers.
The type of identity and access management mechanism implemented to ensure
authentication, authorization, and accountability may vary from one system to the next. A
system containing sensitive information may have a stronger identity and access
management strategy compared to a less sensitive system. The varying levels of strength
of identity and access management mechanism per system are known by the key players
of the organization who established the use of such controls; as a result, mechanisms that
may not be relevant or effective in securing a target system may not be implemented. For
instance, a system classified as top secret may require biometric authentication in
addition to the use of a token, whereas a system classified as confidential may only
require the use of a token. The GST, therefore, explains why a system could become
more secure by introducing varying levels in strength of identity and access management
mechanisms to alter the outcome of that system by reducing the likelihood of a data
breach by malicious insiders occurring.
The literature supports the theme of the use of multifaceted identity and access
management mechanisms. Rao and Selvamani (2015) asserted that fine-grained access
control mechanisms, such as using of credential or attributed based policies, may better
secure access and data processing. The assertion made by Rao and Selvamani links my
research study’s findings back to the concept of function, structure, and process, which
portray the GST as the conceptual framework for this study. The function of gaining
access to a system within a specific structure follows an implemented process that can
permit or reject a user’s access to data. The output of such activities within a system is the
ability to strengthen the target system’s security, as well as providing the capability to
monitor user access activity. Chang and Ramachandran (2016) asserted that the use of
identity and access management strategies promotes user security and monitoring.
The literature also strengthens the finding that links the use of multifaceted
identity and access management mechanisms to data security management strategies that
may be used by organizations to prevent data breaches by malicious insiders. Wang, Pei,
and Zhang (2019) found that identity management becomes a key problem in a system
when design defects persist, as direct risks of a data breach will be incurred. Identity and
access management is the first technical layer of defense users, both privileged and
nonprivileged, go through to access a system. All eight interviewees indicated support for
effective identity and access management controls by noting that identity and access
management is a key organizational security control to minimize malicious insider
threats, which may lead to data breaches. Pol (2019) also asserted that the deployment of
identity and access management mechanisms are essential controls that enable an
organization to detect or prevent data breaches resulting from unauthorized access to
systems. From the literature, there is an alignment with the finding that the use of
multifaceted identity and access management mechanisms are data security management
strategies that may help organizations prevent data breaches caused by malicious insiders.
Theme 3: Use of Security Frameworks Specific to Organizational Needs
The need to use security frameworks specific to organizational needs was another
theme that emerged during data analysis. Organizations must comply with the
overarching governmental mandates and regulations set forth by their regulating and
other governing bodies. From my analysis of both case study organizational interviews
and documentation collected, I noted that data security management strategies must align
with the policies that result from the rules and regulations that govern a specific
organization. For instance, Company A falls under the department of defense space and
complies with the Federal Information Security Management Act (FISMA) and NIST
requirements. These are frameworks that help to protect data, operational information,
and assets against threats, including data breaches caused by malicious insiders. Based on
the analysis of findings, there is a need for ongoing compliance with the regulations
governing an organization. Over time, the frameworks change, and new controls are
added. When that happens, a review of the existing practices is performed, and policies
are updated to conform to the updated security framework. Organizations, therefore, must
repeatedly review and assess how they are complying with regulations and guidelines set
forth by external stakeholders, to remain compliant.
Table 5
Frequency of Third Major Theme
Participant Document Direct Observation
Major/Minor
Theme
Count
References
Count References Count References
Use of
security
frameworks
specific to
organizational
needs
5
28
5 253 1 4
Note. Theme 3, use of security frameworks specific to organizational needs; n =
frequency.
Both participant organizations indicated that the use of some form of an
industryspecific security framework that fits organizational needs is key to employing
data security management strategies to prevent data breaches. For instance, the NIST
framework requires organizations to establish insider threat programs, which is a
mechanism that could be used to train organizational personnel on how to detect and
report suspicious insider activity. An organizational culture that is well-equipped with
insider threat management programs may stand a greater chance of preventing data
breaches by malicious insiders. Company B P1 noted that complying with organization
security policy allows the organization to remain in compliance at the federal government
level. Company A P1 stated that “anything we have implemented is based on FISMA
compliance guidelines,” and noted the need to seek external assistance: “our management
should make this kind of decision to seek help from outside consultants to make sure and
are following FISMA compliance.” In response to the interview question of what
programs are used to ensure that users or staff are compliant with data security
management protocols, Company A P2 stated that they use security compliance templates
that are built on STIGs. The information provided by the interviewees underscores the
cruciality of ensuring the most recent and updated versions of security framework
policies and regulations are followed.
The data collected from both organizations also shows that security frameworks
do not always have to be technical to be effective but can also be administrative in nature.
For instance, Company A P4 stated that:
policy is just probably the biggest tool we are using in the ways of security
awareness training, where they take that annually, just so they’re aware of
phishing and what they shouldn’t be clicking on, and what they shouldn’t be
transmitting, and then policy to back that up in the event that somebody actually
does do that.
A malicious insider with easy access to an organization’s email system could easily
obtain email addresses of employees and easily distribute an insecure link to other users
on the network who may click on the link to collect sensitive data. On the technical side,
one measure to ensure that new systems or changes to existing ones do no introduce
vulnerabilities into the enterprise which could be taken advantage of by malicious
insiders was noted by Company A P4:
we’ll have our security team use their security tool to scan it for compliance
against the CIS benchmark, and we have a threshold of, maybe it has to meet a 90% of
the CIS benchmark, just because it will flag everything as negative and that will be
detrimental to the organization from locking it down too much. The note from Company
B P4 indicates the need for organizations to ensure that security controls put in place are
not overbearing, leading to low productivity levels of personnel. Company A P2reflects
evidence of this approach by stating that “there are NIST and FISMA guidelines, among
others that do assist with coming up with the security policies and guidelines from the
enterprise level, and database in particular.” The theme of using security frameworks
specific to organizational needs that emerged from the data collected confirms the
necessity for organizations to include the use of security frameworks as part of their data
security management strategy.
The organizational documents that were collected for data analysis supported the
importance for an organization to follow an industry-specific security framework, and the
necessity to comply with the policies and regulations set forth for that organization. The
need to validate the specific framework is applicable and effective is another essential
aspect of this theme. Company B P2 asserted that “the guideline should be
doublechecked; there should be a system in place to make sure whatever security policy
you have put in place is working.” The wealth of data collected and the findings from
interviews, member checking, direct observation, and document analysis led to
methodological triangulation for the theme of the use of security frameworks specific to
organizational needs.
The literature supports the theme of using security frameworks that are specific to
organizational needs as a data security management strategy to prevent data breaches by
malicious insiders. Chang and Ramachandran (2016) noted in their work on cloud
computing adoption frameworks that a multilayered framework provides more
finegrained defense countermeasures to better protect an organization and its assets.
Moreover, recent literature supports further the theme of using security frameworks
specific to organizational needs. Anisetti, Ardagna, Damiani, and Gaudenzi (2017) noted
that it is equally critical for organizations to measure the effectiveness of the security
framework in use by conducting audits on the systems on which the security framework
is applied. Pacheco, Tunc, and Hariri (2018) in their study of security frameworks for the
Internet of Things (IoT) stated the need for frameworks to be trustworthy, secure, as well
as meet security needs at every layer of a system, instead of in an ad-hoc and afterthought
manner. Based on the findings of this study and literature, the data support the need for
organizations to have a comprehensive, yet relevant, security framework implemented as
an integral aspect of their data security management strategy.
The theme of use of security frameworks specific to organizational needs aligns
well with GST as the conceptual framework for this study because GST considers
elements within a system, a company in this case, that can influence the outcomes, a more
robust system due to an enhanced data security management strategy, leading to an
altered output from the system, a reduced likelihood of data breaches caused by malicious
insiders. Based on a study conducted by Iwu, Kapondoro, Twum-Darko, and Lose
(2016), the GST is a good lens to use for the study of the relationships between
components in a system, to measure outcomes based on criteria or input.
A data security management strategy must be comprehensive to identify and
include the various components that work together in a system. The relationships
established, facilitate easy identification of strengths and weaknesses within the system,
allowing reinforcements to be made. For instance, a weakness in a logical security control
that manages user authentication to a server can be identified and remediated by
supplementing with the implementation of physical control of the use of a secured server
room that is not accessible remotely. The goal of implementing a security framework is to
ensure the certainty of the end goal, which is a more secure system. Additionally,
tracking the effectiveness of the security framework implemented is a vital activity that is
performed to ascertain that the security controls are working. Therefore, the theme of the
use of security frameworks specific to organizational needs aligns with the GST, whereby
a specific outcome is required based on inputs to a system.
Theme 4: Use of Strong Technical Operations Management Mechanisms
The final theme to emerge from data collection and analysis was the use of strong
technical operations management mechanisms. The theme of the use of strong technical
operations management mechanisms encompasses establishing system baselines,
applying data encryption, following industry best practices around backup strategies, and
security auditing. Baselines are used for comparing the original or ‘gold’ state of a system
to the end state of that same system after changes are performed.
Cases, where benchmarks are used, include capturing network traffic patterns over
a specific period, provisioning a server with a ‘previously hardened’ configuration
template, and establishing the original code base for an application in a code repository.
Baselines aid in the assessment of deltas between the original and end states of a system
(Edgar et al., 2004). After identifying the changes between the old and new states of a
system, anomalies can then be flagged for review.
Encryption is an effective technique to ensure confidentiality and integrity in
systems. Encryption techniques can be used to protect data that is stored within systems,
as well as when data is transferred or moved from one system to another, also known as
point-to-point encryption. The type of data determines the type and strength of the
encryption technique that is considered. The purpose of encrypting data while at rest and
in-motion is to prevent unauthorized access and preserve the principle of need-to-know.
One of the most effective strategies for data loss is backup restores, keeping in
mind the recovery point and time objectives of an organization. Backup strategies must
be a functional and frequently reviewed activity in an organization. Backups can be full
or incremental, including transactional and differential backups, or a combination of the
options mentioned, depending on the needs of the organization. Conducting backup
recovery exercises to guarantee the effectiveness of the backup strategy in use is a crucial
activity.
Another strategy to prevent data loss is the use of data loss prevention (DLP)
solutions on employee workstations. Email and file transmissions are monitored to detect
egress of data that violate organizational policy, leading to the prevention of data breach
attempts by malicious insiders. Additionally, DLP tools may also be configured to
minimize phishing attempts to exfiltrate data through filtering controls to ensure PII data
is not being sent outside the organization. Preventing the use of external and thumb drives
by disabling universal serial bus (USB) ports is another data loss prevention technique.
Locking down USB ports prevents database and system administrators from transferring
data without going through the appropriate data transfer channels. In cases where flash
drives are required to transfer large amounts of data, approvals for exceptions are
obtained and specially encrypted drives are provisioned to database and system
administrators. After usage, the flash drive is then wiped and made ready for future use.
Conducting security auditing provides system custodians a way to monitor events,
review logs, and identify any threats that could impact the confidentiality, integrity, and
availability of the system entrusted to them. Security auditing can be either proactive, in
the sense of administrators conducting regular reviews of the system to detect
unauthorized actions and anomalies, or reactive, for example, when investigative
activities are conducted to detect the root cause of an incident. Although contingency
planning and incidence response planning do not prevent data breaches, they go together
with back up strategies that an organization may choose to leverage. Contingency plans
help organizations minimize or prevent a disruption in operations while pursuing a
response to an incident. For instance, should there be a data breach that causes loss of
data, the organization can failover their operations to an alternate site by activating their
contingency plan, while leaving the state of the current system in a contained state while
incidence response and investigative activities are performed.
Table 6
Frequency of Fourth Major Theme
Participant Document Direct Observation
Major/Minor
Theme Count References Count References Count References
Use of
security
frameworks
specific to
organizational
needs
8 188 5 185 1 17
Note. Theme 4, use of strong technical operations management mechanisms; n =
frequency.
All eight study participants from both organizations revealed the importance of
using strong technical operations management mechanisms as data security management
strategies to prevent data breaches. Participant 2 from the same organization also noted
that database backups are encrypted and cannot be restored without knowledge of the
password used for encryption. About backup strategies, Participant 2 from Organization
A said that:
if we find out that data is corrupted, hopefully, we have a backup of that data on
the disc, and the system administrators side of it, in the use of VMware,
hopefully, they do have...I know it is very advanced now, where they can check
block-by-block snapshots, so we can restore up to the point-in-time, which was
detected that data was corrupted, so we don't really lose much data.
Participant 1 from Organization B also stated that “we have daily backups that we take,
and we also have data gaps, which is a live backup set – which is replications.”
Additionally, Participant 3 from the same organization stated that “there is always a site
at a certain location where we have a backup system where we get replication through the
current system up to the minute.” Uninterruptable Power Supply (UPS) is another form
of backup strategy which can help to prevent data loss should there be a power outage.
Finally, on the subject matter of auditing, Participant 2 from Organization A
remarked that auditing is performed as part of their baselines review activities. Participant
3 from Organization B also stated that “we rely on the sysadmin team to get the process
ID and session information and look into the audit file to see what the login or database
account was used to get into the system.” Participant 4 from Organization B mentioned a
dedicated IT audit department assists with unauthorized access and intrusion detection.
Additionally, two often overlooked areas of auditing are data transfer and destruction.
Participant 1 from Organization B stated that printing activities of users are tracked,
including who printed, what they printed, and which printer was used. Dumpster diving is
a threat vector to these two phases of the lifecycle of data. Malicious insiders do not use
shredders dedicated for destroying printouts or extracts that contain sensitive information,
but rather throw the printouts away, only to retrieve them later.
Furthermore, data salvaging by malicious insiders from the hard drives of
decommissioned servers poses a threat to organizational data security safeguards. For
instance, a hard drive containing trade secrets could be sold at a lucrative price to a
competitor organization, which could gain a competitive advantage over the victimized
organization. Therefore, tracking data transfers and destruction is a critical component of
a holistic data security management strategy.
The importance of this theme was highlighted after conducting an analysis of four
organizational documents and allowing for methodological triangulation. The AC-2(4)
control of the NIST SP 800-53 (Rev. 4) document notes the need to automatically audit
information systems for account creation, modification, enabling, disabling, and removal
actions, and notifying the appropriate personnel of the actions that were performed on the
system. A document titled CIS Windows Benchmark discusses over 80 references of use
of strong technical operations management mechanisms, including auditing rights
assignments and security policy changes on a system, account management events,
ensuring entire system backups are performed, and encrypting system drives using a tool
called BitLocker. Another organizational document referred to the use of backup power
supplies as part of the contingency strategy, the use of an independent third party for
system auditing, as well as performing annual in-house auditing.
The literature aligns with the findings from the theme of using strong technical
operations management mechanisms. Forde (2017) asserted the need for businesses to
encrypt their sensitive data to avoid the possible loss clients and the expenses associated
with reporting breaches. Jingguo et al. (2015) noted that a strong mitigation technique
against threats to data and services availability is the use of real-time backup images
stored offsite. In the event where organizations use cloud service providers for storage
needs, relying on a third-party auditor to conduct compliance to service level agreements,
monitoring feedback for service utilization, and the possibility of any potential insider
threats or attacks, demonstrate efficiency and effectiveness when auditing all key
stakeholders (Razaque & Rizvi, 2016). Concerning contingency plans, Caruso (2003)
stated that contracting organizations must include contingency responses to disasters and
security controls, for both vendors, and on the organization outsourcing its IT.
More recent literature additionally supports the theme of the use of strong
technical operations management mechanisms and aligns with the findings. Deprecated
performance is a known effect of encryption. Despite the performance risk, Chen, Hu,
and Li (2019) assert that data encryption has become an indispensable step in protecting
privacy. The use of symmetric encryption can help alleviate the performance issues often
noticed with the implementation of data encryption on large data sets. Zhang and Li
(2017) noted that not only should backups be created by anyone in the organization, but
also backup strategy techniques must include authentication based on digital certificates,
role-based access to backups, baked-in process and auditing, detection of legitimate
backup storage and restore target. This approach discussed in conjunction with other data
breach detection techniques may be effective in minimizing the likelihood of data
breaches caused by malicious insiders. On the subject-matter of contingency plans and
incidence response, Padilla and Freire (2019) assert that not only do companies have to
have such strategies in place as part of their organizational policy, but also to prevent
economic damages from attacks. Economic damages may include lawsuits, costs incurred
from switching systems from production to the contingency site, and reverting to
production after remediation activity is completed. The objective of conducting security
audits is not only to improve an organization’s risk management process but, more
importantly, to hold the responsibility of legal compliance (Satoh & Samejima, 2017).
Auditing provides organizations insight into the effectiveness of organizational policy
and processes so that adjustments can be made, should they be proactive or reactive.
The theme of using strong technical operations management mechanisms aligns
well with the GST as the conceptual framework because GST explains the effect on the
relationships between elements that constitute a system. In this case, using the GST as the
lens for this study shows the result of the data security management technique of
leveraging strong technical operations management mechanisms in an organization, to
prevent a negative outcome, a data breach. Von Bertalanffy (1972) discussed how the
interdependence of objects working together could yield some result rather than the
objects working in isolation. The interview participants indicated a variety of techniques
are necessary to ensure defense-in-depth to better protect data from malicious insiders. In
contrast, although the grey systems theory, a contradicting theory to the GST, can be
useful in evaluating relationships, the theory focuses on uncertain components and
outcomes of the subject system (Li, 2016). The goal of participant organizations of the
study leveraging a mixture of data security management strategies is to ensure exploitable
threats within the system that could be exfiltrated by malicious insiders to cause data
breaches are mitigated. Therefore, the grey systems theory contradicts the emerged theme
of the use of strong technical operations management mechanisms to prevent data
breaches.
Applications to Professional Practice
The issue that formed the basis of this study is the perceived lack of strategies
used by database and system administrators in small-scale government contracting
organizations to prevent data breaches caused by malicious insiders. The application of
data security management strategies by organizations contributes to the prevention of
unwanted and unexpected expenses that could be incurred from data breaches (Padilla &
Freire, 2019). The findings in the study resulted in some key themes that other
organizations can use as part of their strategies to enhance their data security management
strategies to prevent data breaches carried out by malicious insiders. There were various
thoughts on the data security management strategies, implying that there are several
strategies in use in the IT field, where the implementation of those strategies depends on
the needs, and regulations that govern an organization. Most of the participants noted that
they relied on training, security frameworks, and technical strategies tailored to their role
and organization instead of a generic strategy. After analyzing the collected data, I
identified four themes: enforcement of organizational security policy through training,
use of multifaceted identity and access management techniques, use of security
frameworks, and use of strong technical control operations management mechanisms.
Organizations and IT practitioners in their role of protecting data from malicious insiders
can use the results of this study.
Organizations that store data which, when breached, can cause grave damage
either to their customers, the organization itself, or nation, can use these results to
establish or enhance their organizational policies and strategies they use to secure their
data. Moreover, the findings of this study may be valuable in professional practice by
helping database administrators and system administrators to expand their knowledge and
understanding of the complex nature of insider threat and how it relates to data breaches.
An effective data security management strategy can improve the security posture and
culture of an organization, such as the overarching data security management policies in
place, leading to a more robust framework to promote data confidentiality, integrity, and
availability.
Implications for Social Change
The findings of this study add to the existing body of knowledge and literature by
contributing information and knowledge on data security management strategies for
preventing data breaches by malicious insiders. This study’s findings may also influence
positive social change by bringing focus and awareness to the management of sensitive
data and protecting access to data from malicious insiders. The data from the study
emphasizes the conclusions drawn reflected in the emerged themes to be beneficial for
the implementation of data security management strategies.
The value this study brings to society is that it shows how organizations can
implement strategies to secure their data to ensure confidentiality, integrity, and
availability, and ultimately prevent the damages that can be caused by data breaches. The
study’s findings show that many of the participants agree on a variety of strategies, to
include organizational policy enforcement through training, the use pf multifaceted
identity and access management techniques, the use of security frameworks geared
toward organizational needs, and use of strong technical operations management
mechanisms. The growing need to secure sensitive data has influenced a variety of
solutions to be implemented based on implementations known to be successful in
preventing data breaches across the IT industry.
Beneficiaries of effective data security management strategies include customers,
employees, the government contracting organization, organizational partners, vendors of
the systems in use by the government contracting agency, and the government agencies
for which the contracting organization performs work. The highest effect of damage is
felt by the citizen whose information may become compromised in a data breach. Identity
theft resolution could sometimes take years, and in some cases, the harm caused to the
individual may be irreversible.
In cases where malicious insiders disclose national secrets to foreign adversaries,
reveal trade secrets to competitors, or leak classified information to citizens without a
need-to-know, the relationship between the organization and its clients or partners
becomes tarnished, and international relations and partnerships suffer. A more secure
system builds trust between organizations and their clients, as well as vendors and
business partners. The benefit of such a relationship could result in increased profitability
for an organization and foster better international relations with allies.
Finally, an organization with effective data security management strategies builds
trust, reliability, and confidence with the agency work is being performed, resulting in a
win-win scenario. Trust, reliability, and confidence could lead to additional contracts
being awarded, and in the long run, a profitable outcome for the organization. Moreover,
citizen information is better secured from threats that may be imposed by malicious
insiders.
Recommendations for Action
The employees of an organization are the first line of defense for securing data,
which is one of the most valuable assets of an organization. More so, privileged
employees, including database administrators and system administrators, are entrusted as
the custodians of organizational data, therefore, have direct access to data with no
restrictions based on their role and clearance level. The nature of the type of access given
to users, including database and system administrators, creates a risk for an organization
if these trusted insiders become malicious. To mitigate or reduce the likelihood of the
threat of malicious insiders, a layered-security approach is key to provide in-depth
safeguards against data breaches.
As suggested by the participants of this study, organizations should ensure users
are trained as a strategy to enforce organizational policy, use a multifaceted approach for
identity and access management, ensure that the security frameworks being used fit
organizational needs, and use strong technical operations management techniques. The
suggested strategies ensure that a holistic solution is implemented to protect data in all
phases of its lifecycle, from creation, through use, and transfer, to destruction. Findings
from this study are important to data custodians, information system owners, and
organizational data security policymakers.
The two case study organizations and contacts will receive copies of the results of
this study through email so it may be propagated to data security management matter
experts who could share the findings with personnel within their purview and sphere of
influence, as well as others in the broader scope of ensuring data security within their
organizations. My immediate goal is that this final study will be published and made
available for public searches when companies are in search of data security management
strategies to prevent data breaches. As a long-term goal, I intend to share, wherever
possible, the results using appropriate and effective platforms, including my place of
work, conferences, training seminars, and data security management stakeholders in the
broader research community.
Recommendations for Further Study
Malicious insiders continue to pose a threat to the organization, and sometimes the
impact from data breaches can be grievous, and the damage irreversible. Insider attacks
are motivated by several reasons and carried out several forms, especially when it comes
to data destruction. Some organizations participate in programs where old servers are
given away to charity organizations within the country or abroad. When proper
techniques are not used to destroy remnants of data left on hard drives after
decommissioning, a malicious insider could take advantage of this loophole due to inside
knowledge. Therefore, the proper strategies in use for data destruction at the end of the
data lifecycle should be investigated further to assist in determining the views held by
database administrators and system administrators in this regard. Also, the results of the
study depend significantly on the experiences of the participants, as well as the sample
size of the study. I recommend that researchers interview large-scale government
contracting organizations, or simply, private organizations, to cover participant
experiences in those types of settings. To further shed light on data security management
strategies in use by database administrators and system administrators to prevent data
breaches by malicious insiders, researchers may consider a study into the factors that
motivate malicious insiders to perpetrate data breaches.
Reflections
A statement made by one of the participants struck a chord with me. The
participant asserted that what a user does with depends on what that user has been trained
for, and I would like to add that it also depends on the motives of the user. As the
researcher, I was the main instrument for data collection and analysis. The research
process was an eye-opening experience for me as I had the opportunity to learn about
strategies the participants of my study use to prevent data breaches. There is a great deal
of potential for organizations to utilize their data security management strategies across
the data life cycle. As a researcher, having worked with databases in my career, it was
interesting to learn about the perspectives of other professionals who ensure data does not
reach the wrong hands. As such, I took necessary precautions to minimize personal bias
by avoiding injecting any personal values, subjective views, and inclinations. I strived to
learn throughout the research activities, including recruiting participants, member
checking, direct observation, and the data collected as part of this study. I ensured the
credibility of the study and immersed myself in looking at things from a variety of
perspectives. An example of this is that organizational policy changes are not only
influenced by regulations mandated by governing bodies in a top-to-bottom fashion, but
also the activities of a hacker, and malicious insider activities, following a bottom-up
approach.
Summary and Study Conclusions
In my endeavors to explore strategies in use by database administrators and
system administrators to prevent data breaches by malicious insiders, I discovered the
complex nature of insider threat, and on a good note, strategies that can be used to reduce
the likelihood of data breaches by malicious insiders. The motivations of malicious
insiders continue to influence the perpetration of data breaches. Enhancing the
organizational security culture to a level where employees are trained to identify
symptoms of a potential insider threat, a policy on how to handle such a threat, and when
to report such threats can assist in stopping or minimizing the occurrence of data
breaches. Managing insider threats should be baked into the policy of an organization to
create a heightened awareness. Implementation of such a policy, in conjunction with the
themes identified from the data collected for this study, could provide an organization
with an arsenal of counter insider threat measures. The use of methodological
triangulation ensured the themes and findings of this study across a range of data sources
to be validated. The interview participants involved in this study have had success in
preventing data breaches from the implementation of the data security management
strategies they use at their respective organizations. Having identified the emerged
themes between the two participant organizations, the study’s findings could have a
significant influence and impact on the data security management strategies in use by
other organizations in the government contracting sector. The findings and conclusion of
the study may contribute to social change because the strategies identified can be
implemented across the entire organization, to protect sensitive data better, and prevent
data breaches that could negatively impact customers, citizens of a nation, the
organization itself, partners, vendors, and the nation at large.
Students also viewed