Presenter: Carl Willis-Ford, Senior Principal
Many information security groups categorize Insider Threat as either 'malicious' or 'unintentional'. Research shows that there is a significant number of insider security policy violations that are non-malicious, but intentional. These are employees that view security policy as an obstruction to getting work done, or as an inconvenience. Non-malicious security violations can directly cause breaches or indirectly assist either malicious insiders or external attackers. The presentation will all three aspects of Insider Threat and offer research-based approaches to manage the threat.
Bio: Carl Willis-Ford is a senior solution architect for CSRA, leading teams in designing technical solutions to meet or exceed the requirements of Federal Health agencies. Willis-Ford started his career as a nuclear reactor operator on fast attack submarines in the U.S. Navy. Post-Navy, he worked as a federal civilian at Puget Sound Naval Shipyard until joining SRA (now CSRA) in 1997. He received an Individual Excellence award from SRA in 2013.
He holds a B.S. in Computer Science, an M.S. in Network Security, an M.S. in Technology Management, and is currently in a Doctorate in Information Assurance program (expected 2018).
Willis-Ford is a member of the Technical Working Group of the Federal Information Systems Security Educators’ Association (FISSEA), an Industry Advisory Board Member for the National Cybersecurity Student Association, a member of the Collegiate subgroup of the National Initiative for Cybersecurity Education Working Group, and is a Senior Member of the NOVA chapter of ISSA.
He has given security presentations at the International Oracle Users Group, NIST conferences, and George Mason University; and is a regular guest presenter for NASA’s security awareness program.