Insider risk · 3.2
What detection can and cannot establish
What detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
Where workforce visibility is separately justified and disclosed, employee activity tracking describes a related monitoring use case; it should not be treated as proof of intent.
For an independent reference point, see ICO guidance on monitoring workers.
What a record establishes
Four facts and no more
That an event occurred. When. Which account performed it. On which system.
Everything beyond those four is inference, and the distance between the four and a conclusion is where investigations go wrong.
What it does not establish
Three things people read into it
Who. A record identifies an account. Whether the person it belongs to was at the keyboard is a separate question, particularly where credentials are shared, which on a shop floor they frequently are.
Why. A file copied at two in the morning may be theft, may be somebody finishing a job before a deadline, and the record looks identical.
Whether it mattered. Whether the file was covered, whether the destination was authorised, and whether any harm followed are business questions answered by people who know the work.
Baselines
Unusual is not wrong
Detection compares behaviour against a baseline and reports departures. Departures are common and mostly benign: a new project, a different shift, an audit, a person covering for a colleague.
A system reporting anomalies reports change. Turning change into risk requires context the system does not have, which is why the output is a signal for a person rather than a finding.
The evidentiary question
Different decisions need different confidence
Asking somebody a question needs very little. Removing access pending an enquiry needs more. An employment decision needs a great deal and needs to withstand scrutiny in a forum with its own rules. A report to a customer or a regulator needs facts you can stand behind.
Deciding in advance which threshold applies to which action prevents the pattern where a single anomalous record produces a confrontation.
Investigation is human
What the tool hands over
A timeline and a set of records. What follows is asking the person's manager whether the activity fits the work, checking whether a project explains it, and, where appropriate, asking the person.
That work cannot be automated and organisations that buy detection without allocating it end up with a queue nobody processes, which the entry on false positives describes.
What it is good at
The cases where records are decisive
Establishing scope after something is known to have happened. Answering the question an assessor or a customer asks about which files were affected. Demonstrating that a control operated. And detecting bulk activity that no ordinary work explains.
Those are real and they justify the capability. Attributing intent is not among them.
The honest claim
What a vendor should say
That the system records file activity and identifies patterns worth a human look. Anything stronger, and particularly anything about identifying malicious insiders, is a claim about intent that no detection makes.
This site says so on the platform page, which is unusual and is the accurate description.
Correlating across systems
Where the clocks matter
Reconstructing a sequence across a file server, an identity system and a machine requires their timestamps to be comparable. The blog entry on forensic readiness makes the same point and it applies to routine investigation as much as to incidents.
Time synchronisation is unglamorous and it is the difference between a narrative and a pile of records.
Also
Elsewhere in insider risk
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.