Insider risk · 3.1

What insider risk actually covers

What insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see ICO guidance on monitoring workers.

The term

It carries a connotation that misdescribes the problem

Insider threat suggests a person deciding to harm their employer. That happens and it is the smallest of the three categories the phrase covers.

Using the dramatic reading to design a programme produces surveillance aimed at a rare event while the common ones continue unaddressed.

Three categories

Malicious, negligent, compromised

Malicious. Somebody with legitimate access using it deliberately against the organisation: theft of designs, sabotage, taking material to a competitor. Real, serious, and uncommon.

Negligent. Error, convenience and drift. The file emailed to the wrong supplier, the copy taken home to work on, the memory stick, the shared login. This is the great majority.

Compromised. An outsider using an insider's credentials. Technically an intrusion and behaviourally indistinguishable from the insider until somebody looks, which is why detection built for one finds the other.

Where the requirement sits

Distributed across families, not a single control

The standard does not have an insider threat control. It has personnel security, access control, audit and accountability, identification and authentication, and media protection, and the insider question is answered by the combination.

Which means a supplier can address it substantially without buying anything labelled for the purpose, and the entry on what is not required applies.

What a programme contains

Six things, only one of them technology

Access granted by role and reviewed. Separation of duties where the size of the organisation permits it. Records of who did what. A departure process that runs on the day. A channel for people to report concerns. And detection that produces a small number of signals worth looking at.

The first five are process and cost little. The sixth is where a product helps and it is the last one to reach for rather than the first.

The people question

Personnel security, briefly

The standard expects screening appropriate to the role and a process covering transfers and departures. What screening is appropriate depends on the work and, for some programmes, on requirements outside this standard entirely.

This is an employment law question as much as a security one and it is handled with advice rather than by policy download.

Proportion

Design for the common case

If the great majority of what you will encounter is error and convenience, the highest-value work is making the correct action easy and the incorrect one visible. That is the argument of the blog entry on how a control looks from the machine, arriving from a different direction.

A programme designed for the rare malicious case tends to produce controls people resent, which increases the common case.

Saying it out loud

Tell people what the programme assumes

That most of what it finds will be mistakes, that mistakes reported early are welcome, and that the point is to protect the contracts everybody's job depends on.

Stated once, publicly, this changes how the whole thing is received. Left unstated, people assume the dramatic reading, because that is what the words suggest.

The reporting channel

People notice things before systems do

A colleague behaving unusually, a contractor asking odd questions, a door propped open. Most of what is worth knowing arrives from a person, and only if there is somewhere to take it and a belief that something will happen.

The blog entry on unworkable controls describes the same channel serving a different purpose, which is an argument for having one rather than two.

Also

Elsewhere in insider risk