Page 165 - CISSO_Prep_ Guide
P. 165

errors may be incorrect listings of experience, certification,
            education, or responsibilities. When an organization hires a new
            employee or even engages a contractor or consultant, it is
            important to verify the claims made in the application and
            determine whether the prospective employee actually has the
            necessary skills to do their job. An organization may also want
            to perform criminal record checks on an employee that may be
            in a trusted position.




            Termination of Employment
            When an employee is leaving the organization, it is critical to
            remove their access. Ensuring that if they have been able to use
            their own devices that no corporate data is remaining on the
            device.

            Conducting an exit interview with a departing employee can
            also be a good manner of gathering information about strengths,
            weaknesses, and possible improvements that can be made to the
            organization.

            When an employee or contractor leaves under involuntary terms,
            it is often advisable to escort them off the premises and ensure
            that all access accounts are disabled immediately.



            Social Engineering
            Social engineering is the manipulation of people to commit
            illegal or unauthorized activity. Social engineering is one of the
            most serious threats today. In many cases, the way an attack was
            successful was through the manipulation of people and the
   160   161   162   163   164   165   166   167   168   169   170