Edward Snowden’s action demonstrated that an ordinary insider with a U.S. security clearance can intercept and distribute highly confidential information. Organizations need a risk-based approach to security, in addition to compliance. Data and information is at the core of invasion risk from such challenges as the Advanced Persistent Threat. The American Society of Civil Engineers recently gave US infrastructure a grade of D+ in this area, citing many critical deficiencies. Security should be as simple and user friendly as possible, but still adequate to meet the needs of the organization.”]

