Page 165 - CISSO_Prep_ Guide
P. 165
errors may be incorrect listings of experience, certification,
education, or responsibilities. When an organization hires a new
employee or even engages a contractor or consultant, it is
important to verify the claims made in the application and
determine whether the prospective employee actually has the
necessary skills to do their job. An organization may also want
to perform criminal record checks on an employee that may be
in a trusted position.
Termination of Employment
When an employee is leaving the organization, it is critical to
remove their access. Ensuring that if they have been able to use
their own devices that no corporate data is remaining on the
device.
Conducting an exit interview with a departing employee can
also be a good manner of gathering information about strengths,
weaknesses, and possible improvements that can be made to the
organization.
When an employee or contractor leaves under involuntary terms,
it is often advisable to escort them off the premises and ensure
that all access accounts are disabled immediately.
Social Engineering
Social engineering is the manipulation of people to commit
illegal or unauthorized activity. Social engineering is one of the
most serious threats today. In many cases, the way an attack was
successful was through the manipulation of people and the