Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Manual home / Contents / Chapter 04

Chapter 04 · Controls

Building an insider risk programme

Written for the person asked to stand up a programme, or to explain to a board why one already exists in pieces.

Decide the scope before the tooling

Programmes fail at the scope stage far more often than at the technology stage. Four questions settle the shape of everything that follows, and answering them in writing is the first deliverable.

What are we protecting?
A specific, bounded list of material and systems. "Everything" is not an answer, because it produces controls that are uniformly weak.
From which categories?
The four in chapter 2 need different controls. Most programmes should say plainly that accidental exposure and intellectual property theft are the priority and that sabotage is a privileged-access problem addressed separately.
Who decides to look at a person?
A named function, not a named individual, with a written threshold and a written record of each decision.
What happens at the end?
The routes out of a case: no action, control change, informal discussion, formal employment process, referral. If a route is not agreed in advance it will be improvised badly under pressure.

The functions involved

An insider case touches several parts of an organisation, and each has a distinct interest that does not reduce to the others. The programme's real work is keeping those interests in the right order.

Table 4.1 — Functions and the interest each holds
FunctionInterestFails by
Security operationsDetection, containment, technical evidenceTreating the case as purely technical
IT and identityAccess accuracy, withdrawal, system contextActing before evidence is preserved
Human resourcesEmployment process, fairness, proportionalityBeing brought in after decisions are made
LegalAdmissibility, privacy obligations, disclosureBeing consulted only when something has gone wrong
The line managerOperational context, work legitimacyBeing the first person told, before the threshold is applied

Procedure: standing up the programme

  1. Write the scope statement and have it agreed at a level that can also agree its cost.
  2. Inventory the material in scope and where copies of it exist, including the copies outside the systems of record.
  3. Map who currently has access to each item, then map who needs it. Publish the gap.
  4. Close the gap by removing access, not by adding monitoring.
  5. Agree the escalation threshold and the authorisation route in writing.
  6. Agree what employees are told about monitoring, and tell them. Chapter 6 covers why this is a control rather than a courtesy.
  7. Only now select tooling, and select it against the categories in scope.
  8. Rehearse one case end to end on a fabricated scenario, and fix what the rehearsal breaks.