Who Was Donn B. Parker?
Donn B. Parker (1929-2021): The Researcher Who Made Computer Crime an Empirical Security Problem
Donn Blanchard Parker was an American information-security researcher who began documenting computer crime when commercial computing was still dominated by central mainframes. At SRI he collected cases, interviewed offenders and victims, advised organisations and police, and argued that security practice should be grounded in observed losses as well as technical possibility.
He is also associated with the Parkerian Hexad, which expands confidentiality, integrity, and availability by adding possession or control, authenticity, and utility. The model asks analysts to state exactly what property of information has been harmed rather than treating every incident as a breach of secrecy.
From Programming to Computer Abuse Research
Parker was born in California on 9 October 1929 and earned a master's degree in mathematics from the University of California, Berkeley. He worked in programming and computer operations at General Dynamics and Control Data during the early growth of large organisational computer systems.
An encounter with a reported computer-related fraud led him to investigate the phenomenon systematically. He joined SRI in 1969 and developed a long research and consulting career around computer crime, information protection, and the behaviour of insiders and organisations.
Computer Crime as a Field of Evidence
Early discussions often treated computer misuse as either ordinary fraud with a new tool or unauthorised access by an exotic technical outsider. Parker compiled cases showing a wider range: data manipulation, theft of services, sabotage, privacy violations, programme copying, and abuse by trusted employees.
He interviewed offenders and victims and examined loss experience across organisations. Case collections have limits because incidents are under-reported and definitions change, but they supplied investigators, legislators, and managers with evidence that the problem was neither hypothetical nor exclusively technical.
The CIA Triad and Its Boundaries
The familiar security triad distinguishes confidentiality, integrity, and availability. Confidentiality restricts disclosure, integrity protects correctness and completeness, and availability keeps information and services accessible when required.
These categories are valuable but can conceal different harms inside broad labels. An encrypted device can be stolen without its contents being disclosed; a genuine record can become unusable through lost software; and a plausible message can be a forgery even when its bits arrive unchanged.
The Parkerian Hexad
Parker's expanded model adds possession or control, authenticity, and utility. Possession concerns custody even before disclosure. Authenticity asks whether data, identity, or origin is genuine. Utility asks whether information remains usable for its intended purpose.
The six properties overlap in real incidents and do not form a mathematical proof of completeness. Their value is diagnostic. Analysts can distinguish a lost decryption key from corrupted ciphertext, a stolen encrypted laptop from disclosed records, and an authentic but unavailable service from a fraudulent one that remains online.
Authenticity in Networked Systems
Digital Signature systems and Message Authentication Codes address important forms of authenticity and integrity, but technology does not decide whether an asserted identity was enrolled correctly or whether an authorised person was deceived into approving a transaction.
Parker's vocabulary encourages a complete chain of questions: who controls the information, which source is claimed, what evidence binds the claim, whether the content remains correct, and whether an authorised user can still make productive use of it.
Law Enforcement and Professional Practice
Parker wrote influential books including Crime by Computer and Fighting Computer Crime, testified before legislatures, and helped train investigators in several countries. His work contributed to the recognition that offences involving computers required technical knowledge, suitable statutes, and preservation of digital evidence.
He also founded SRI's International Information Integrity Institute, bringing large organisations together for confidential exchange on security problems. That forum reflected a practical tension: shared experience improves defence, but victims may avoid disclosure because of legal, commercial, or reputational consequences.
A Deliberate Contrarian
Parker challenged quantitative risk assessment when reliable incident frequencies and loss data were unavailable. He later advocated diligence-based security centred on demonstrable care, ethics, compliance, and business enablement rather than false precision.
The position was controversial, and risk analysis remains indispensable when its uncertainty is explicit. Parker's contribution was to resist security rituals that convert weak assumptions into impressive numbers. Models should clarify judgement, not conceal the scarcity of evidence.
Information Must Remain Fit for Purpose
Parker died on 16 September 2021 after a career that helped turn computer misuse into an international professional concern. The field had grown from mainframe controls to cloud services, mobile devices, ransomware, identity fraud, and global dependency on software.
His legacy is a practical question: what exactly has been lost? Encryption may preserve confidentiality while possession disappears; backups may preserve availability while authenticity is uncertain; intact bits may have no utility. Security exists to preserve valuable use, and precise language helps defenders see which part of that use is at risk.
Back to reading