OWASP SCS Hiring, Remote Work, and Insider Threat Handbook¶
OWASP Smart Contract Security Project
Part of the OWASP SCS Handbook Series. Built to the series conventions.
Purpose and Scope¶
This handbook gives hiring, remote work, and vendor management guidance for Web3 and crypto-native organizations facing a specific and now well-documented threat: state-sponsored IT worker fraud. The guidance follows published advisories from the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the FBI's Internet Crime Complaint Center (IC3) describing how operatives linked to the Democratic People's Republic of Korea (DPRK) obtain remote developer and IT roles at Western companies, then use that access for data extortion, source code theft, credential harvesting, and sanctions-evasion revenue generation. The same infrastructure of fabricated identities, laptop farms, and complicit facilitators supports insider-threat actors beyond a single nation-state, so the controls here generalize past the DPRK case that motivates them.
The scope runs from the job posting to the exit interview and beyond it: recruitment channel hygiene, identity verification for remote hires, red flags visible during interviews and background checks, vendor and contractor due diligence, least-privilege access design for distributed teams, and the detection and response playbooks an organization needs once a hire is suspected of being compromised or malicious. It does not restate general operational security practice covered elsewhere in the series; it applies that practice to the specific moment a threat actor first receives a badge, a laptop, or a commit token.
Target Audience¶
HR and talent acquisition teams, security and IT leadership, hiring managers, and vendor management staff at Web3 and crypto-native organizations. The chapters split along these lines: HR and hiring managers own Parts II and III, security teams own Part IV, and leadership owns the policy and training work in Part V.
How to Use This Handbook¶
Read Part I first regardless of role: it sets the threat context that makes every later control legible, including how DPRK-linked IT workers operate and why their tactics differ from a typical fraudulent applicant. Hiring managers and HR staff working an active requisition should move to Parts II and III for the sourcing, interview, verification, and remote-onboarding controls that apply before and during a hire. Security and incident response staff should jump to Part IV when a hire is already suspected. Part V holds the policy templates and training material leadership needs to institutionalize the program, and Part VI collects the glossary, indicator summary, and checklist for quick reference during a live decision.
Relationship to SCSVS, SCSTG, and SCWE¶
This handbook sits upstream of the OWASP smart contract standards rather than inside them: its subject is the person who writes or reviews the code, not the code itself. The Smart Contract Security Verification Standard (SCSVS) and the Smart Contract Weakness Enumeration (SCWE) assume a codebase already exists to verify or catalog; the controls here reduce the odds that a hostile actor sits inside the team producing that codebase, a precondition neither standard otherwise addresses. The Smart Contract Security Testing Guide (SCSTG) tests what ships; nothing in that guide catches a developer who deliberately plants a vulnerability designed to pass every test. This handbook is closest in scope to the Employee Lifecycle Security Handbook (03), which owns onboarding, access provisioning, and offboarding mechanics once someone is hired, and the Incident Response Handbook (06), whose playbooks this handbook's Part IV extends for the specific case of a compromised or malicious hire.
Contents¶
Part I: Foundations - 1. Introduction to Hiring and Remote Work Security - 2. Threat Context: DPRK and Similar Vectors
Part II: Hiring Security - 3. Job Posting and Sourcing - 4. Interview and Assessment - 5. Vendor and Contractor Selection - 6. Background and Verification (Legal and Practical)
Part III: Remote Work and Overseas Consultation - 7. Remote Work Security - 8. Overseas Consultation and Distributed Teams - 9. After Hire: Post-Hire Behavior and Monitoring - 10. Ongoing Monitoring and Offboarding - 11. Mitigating Insider Threat Actors
Part IV: Detection and Response - 12. Recognizing Potential Compromise - 13. Response Playbook: Suspected Insider or Compromised Hire - 14. Response Playbook: Malware or Phishing Linked to Hire/Vendor
Part V: Hardening and Best Practices - 15. Organizational Defenses - 16. Training for Hiring Managers and HR - 17. Policy Templates and Checklist - 18. References to External Advisories and Resources
Part VI: Appendices - 19. Appendix A: Glossary - 20. Appendix B: Red Flags and Indicators (Summary) - 21. Appendix C: Hiring and Vendor Security Checklist - 22. Appendix D: References, Advisories, and Further Reading