Scope of the guide
This manual treats insider risk as a management subject rather than as a category of alert. It covers how the exposure is created by ordinary decisions about access, how it is bounded by design rather than by observation, what monitoring can and cannot establish, and how a suspected case is handled without destroying the record that later has to justify the response.
The four kinds of case — sabotage, fraud, intellectual property theft and accidental exposure — are kept apart throughout, because they have different motives, leave different traces, and are stopped by different controls. Chapters are written as reference rather than as news, and each carries an applicability line stating who it was written for.