Manual home / Contents / Chapter 04
Chapter 04 · Controls
Building an insider risk programme
Written for the person asked to stand up a programme, or to explain to a board why one already exists in pieces.
Decide the scope before the tooling
Programmes fail at the scope stage far more often than at the technology stage. Four questions settle the shape of everything that follows, and answering them in writing is the first deliverable.
- What are we protecting?
- A specific, bounded list of material and systems. "Everything" is not an answer, because it produces controls that are uniformly weak.
- From which categories?
- The four in chapter 2 need different controls. Most programmes should say plainly that accidental exposure and intellectual property theft are the priority and that sabotage is a privileged-access problem addressed separately.
- Who decides to look at a person?
- A named function, not a named individual, with a written threshold and a written record of each decision.
- What happens at the end?
- The routes out of a case: no action, control change, informal discussion, formal employment process, referral. If a route is not agreed in advance it will be improvised badly under pressure.
The functions involved
An insider case touches several parts of an organisation, and each has a distinct interest that does not reduce to the others. The programme's real work is keeping those interests in the right order.
| Function | Interest | Fails by |
|---|---|---|
| Security operations | Detection, containment, technical evidence | Treating the case as purely technical |
| IT and identity | Access accuracy, withdrawal, system context | Acting before evidence is preserved |
| Human resources | Employment process, fairness, proportionality | Being brought in after decisions are made |
| Legal | Admissibility, privacy obligations, disclosure | Being consulted only when something has gone wrong |
| The line manager | Operational context, work legitimacy | Being the first person told, before the threshold is applied |
Procedure: standing up the programme
- Write the scope statement and have it agreed at a level that can also agree its cost.
- Inventory the material in scope and where copies of it exist, including the copies outside the systems of record.
- Map who currently has access to each item, then map who needs it. Publish the gap.
- Close the gap by removing access, not by adding monitoring.
- Agree the escalation threshold and the authorisation route in writing.
- Agree what employees are told about monitoring, and tell them. Chapter 6 covers why this is a control rather than a courtesy.
- Only now select tooling, and select it against the categories in scope.
- Rehearse one case end to end on a fabricated scenario, and fix what the rehearsal breaks.