Contributor

Back ground checks: Required, but how?

Opinion
Oct 21, 20082 mins
Urine sample

I once worked for an automotive supplier. We were launching a new plant in Tennessee.  We had the equivalent of a casting call in the local community for people to work on the line assembling car seats.  We had trouble getting 120 employees who could pass the mandatory drug screening.  Over 3,000 people applied.  That was an eye opener.

I am guilty of espousing the oft repeated security mandate:  thou shalt perform background checks on all new-hires and contractors.  But just how do you do that?  Someone from HR can call past employers and schools I suppose.  That seems like a lot of work.  Can’t I outsource that?  

70+ advertisers who have bought those keywords.   There were even background check rating sites that would rate the various service offerings which cost as little as $18.  That site linked through to the services they recommend using affiliate urls so their rankings  were suspect and leads me to believe the industry is ripe for abuse.

A Google search on “background check” reveals 25 million web pages and

  launched their approach to background checks today.  A Web 2.0 simple interface allows you to quickly verify a job candidate’s employers etc.   The cost model is based on items you want to check so it could cost $10-90 to verify someone’s claims.  What I really like about BeenVerified’s approach is the transparency offered the individual. They get to approve – on a line by line basis – which aspects of their background an employer can actually check.

BeenVerified just

Screen shot:

If anyone tries this service I would love to hear your thoughts/feedback on it.   My question would be: how would you catch the cyber criminal or even a spy recruited into a foreign espionage service?  Or would you just be increasing the investment the bad guys would have to make in their own recruitment efforts to make sure they got people who checked out clean before inserting them into your organization?

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author