Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Reference manual · nine chapters and a glossary

Scope of the guide

This manual treats insider risk as a management subject rather than as a category of alert. It covers how the exposure is created by ordinary decisions about access, how it is bounded by design rather than by observation, what monitoring can and cannot establish, and how a suspected case is handled without destroying the record that later has to justify the response.

The four kinds of case — sabotage, fraud, intellectual property theft and accidental exposure — are kept apart throughout, because they have different motives, leave different traces, and are stopped by different controls. Chapters are written as reference rather than as news, and each carries an applicability line stating who it was written for.

Start here

  1. 01What insider risk meansWhy the standing exposure and a specific actor are different problems.
  2. 02The four types of insider threatSabotage, fraud, intellectual property theft and accidental exposure.
  3. 03Warning signs and what they are worthObservations that justify a look, and why they are not a test.
  4. 04Building an insider risk programmeThe four scope questions to settle before any tooling is chosen.

Reviewing an access request

The most frequently repeated procedure in this manual, reproduced here because it is the decision that determines how large any later incident can be.

  1. Establish which tier the material sits in before considering the requester.
  2. Confirm the task the access is for, and confirm it is the requester's task.
  3. Grant the narrowest scope that completes the task, not the scope that was asked for.
  4. Set an expiry for anything above role-standard access, and record the approver.
  5. Record what was refused as well as what was granted, so the pattern of refusals is reviewable.
  6. Bind removal to the next role change rather than to a future review date.

The four types at a glance

Table 0.1 — Category, motive, evidence trail and the control that most often catches it
CategoryMotiveEvidence trailControl
SabotageGrievance or retaliationPrivileged change outside change controlSegregation of duties
FraudDirect personal gainSmall repeated transactionsReconciliation and maker-checker
Intellectual property theftTaking work onwardBulk collection then bulk movementEgress review at the leaver point
Accidental threatNone — error or hasteA single misaddressed actionInterface design and a safe reporting route

Chapter 2 takes each category in turn. The glossary defines the vocabulary used across all nine chapters.