Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Manual home / Contents / Chapter 09

Chapter 09 · Response

Glossary

Reference for readers arriving at a single chapter without the preceding ones.

Terms used in this manual

Access review
A scheduled comparison of who holds access against who needs it, ending in removals rather than in a report.
Accidental threat
Exposure caused by error, haste or misunderstanding rather than intent. The most frequent category.
Baseline
An established picture of normal activity for a person or role, without which unusual activity cannot be identified.
Break-glass account
A held-in-reserve privileged account for emergencies. Frequently missed by leaver processes because it carries no personal name.
Containment
Action taken to stop a loss continuing, chosen on the evidence and taken after preservation.
Egress
Movement of material out of a controlled environment, by any route, including permitted ones.
Escalation threshold
The written combination of observations that justifies examining an individual's activity, agreed before any case exists.
Insider
Anyone whose legitimate access derives from a relationship with the organisation, regardless of intent.
Insider risk
The standing exposure created by granting access. Managed, never removed.
Insider threat
A specific person acting or preparing to act against the organisation using their access.
Joiners, movers, leavers
The access lifecycle. The movers step is the one most often omitted.
Least privilege
Granting the minimum access a role requires, for the period it requires it.
Preservation
Securing copies of relevant records before any action that could alter them.
Privileged access
Access permitting administrative or destructive operations, distinguished from ordinary role access by consequence rather than by system.
Segregation of duties
Arranging work so no single person can complete a damaging sequence alone.
Tier
A band of material sharing one granting rule, used so that access decisions are made once per band rather than once per request.