COUNTERMEASURES
- Deterrence
last updated 2012 Oct 29
 
. This page used in the following courses taught by Prof. Richardson
.
BIT 801
.
 
http://www.course.com/catalog/product.cfm?category=Security&subcategory=Security&isbn=0-619-06318-1 Whitman explains in Principles of Information Security, Chpt 3, p. 98

"Deterrence is the best method for preventing an illegal or unethical activity."
"Generally agreed that laws, policies and their associated penalties only deter if three conditions are present:"

  • Fear of penalty
  • Probability of being caught
  • Probability of penalty being administered
..
.
  • Fear of penalty
    • the person thinking about doing the crime, has to fear doing the time. 
    • punishments such as day parole, or non-prison time sanctions might not be strong enough to stop someone
.
.
  • Probability of being caught
    • the person thinking about doing the crime will proceed, unless the believe there is a strong chance they'll actually get caught
    • fear of the punishment doesn't amount to much if they believe that the security forces are not good enough to actually catch them
.
.
  • Probability of penalty being administered
    • the 3rd stage of deterrence is the belief that if I get caught, and there is a penalty, I'll actually have to serve the penalty
    • many people are under the impression that computer and ICT crimes are not considered real crime and that they will be paroled, or let out of jail for non-violent behaviour - therefore the deterrence is low
    • one of the reason that American law enforcement officials tried to develop so much PR for the Kevin Mitnick case was so the public would know he got 5 years in jail and served 5 years
    • see  http://en.wikipedia.org/wiki/Kevin_Mitnick 
.
witiger.com
  CONTACT I MAIN PAGE I NEWS GALLERY I E-BIZ SHORTCUTS I INT'L BIZ SHORTCUTS I MKTG&BUSINESS SHORTCUTS I TEACHING SCHEDULE
.
  MISTAKES ITEXTS USED I IMAGES I RANK IDISCLAIMER I STUDENT CONTRIBUTORS I FORMER STUDENTS I
.
.