Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Manual home / Contents / Scope

Front matter · scope

Scope of the manual

Read this if you are deciding whether the manual answers the question you arrived with.

What this manual covers

This is a reference manual on insider risk written for the people who have to manage it: security leads, IT and identity teams, and the risk and people functions that a case eventually reaches. It covers the subject as a management problem — how the exposure is created, how it is bounded by access design, what monitoring can and cannot establish, and how a suspected case is handled without destroying the record that justifies the response.

How the chapters are ordered

The nine chapters run in three groups. Foundations (chapters 1 to 3) settles what the subject is and how observations should be read. Controls (chapters 4 to 6) covers programme scope, access design and monitoring. Response (chapters 7 to 9) covers handling a case, the shapes cases take, and the vocabulary used throughout. The chapters are written to be read in order but each carries its own applicability line so a reader arriving at one directly knows who it was written for.

What it does not do

The manual does not offer legal advice, and it does not offer a method for judging whether an individual is likely to act. Monitoring scope, notice and retention are regulated differently in different places and belong with an organisation's own legal advisers. Where a chapter touches those boundaries it says so and stops.

Terms

Vocabulary used across the chapters is defined once in the glossary, and chapters use those definitions rather than restating them.