Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Manual home / Contents

Front matter · chapter index

Contents

The complete chapter list, with a one-line abstract for each chapter.

Foundations

  1. 01What insider risk meansSeparates insider risk from insider threat, and sets the boundaries this manual works within.
  2. 02The four types of insider threatThe classification the guide works from: sabotage, fraud, intellectual property theft and accidental threat.
  3. 03Warning signs and what they are worthBehavioural and technical observations, and the reasons they cannot be used as a test.

Controls

  1. 04Building an insider risk programmeScope, governance, the functions involved, and what to write down before starting.
  2. 05Access and data controlsLeast privilege, the joiners-movers-leavers cycle, and segregation of duties.
  3. 06Monitoring, and the limits it works withinWhat monitoring can establish, what it cannot, and why transparency about it is a control.

Response

  1. 07Responding to a suspected insider incidentTriage, evidence handling and the order in which containment steps are taken.
  2. 08Recurring patternsGeneralised shapes that recur across cases, with the trigger and the control for each.
  3. 09GlossaryDefinitions of the terms used across the manual.

Front matter

  1. ·Scope of the manual What the manual covers, how the chapters are ordered, and where it stops.