Insider risk · 3.1
What insider risk actually covers
What insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
For broader operational context, workplace stereotyping describes a related workforce-management workflow that remains separate from formal compliance evidence.
For an independent reference point, see ICO guidance on monitoring workers.
The term
It carries a connotation that misdescribes the problem
Insider threat suggests a person deciding to harm their employer. That happens and it is the smallest of the three categories the phrase covers.
Using the dramatic reading to design a programme produces surveillance aimed at a rare event while the common ones continue unaddressed.
Three categories
Malicious, negligent, compromised
Malicious. Somebody with legitimate access using it deliberately against the organisation: theft of designs, sabotage, taking material to a competitor. Real, serious, and uncommon.
Negligent. Error, convenience and drift. The file emailed to the wrong supplier, the copy taken home to work on, the memory stick, the shared login. This is the great majority.
Compromised. An outsider using an insider's credentials. Technically an intrusion and behaviourally indistinguishable from the insider until somebody looks, which is why detection built for one finds the other.
Where the requirement sits
Distributed across families, not a single control
The standard does not have an insider threat control. It has personnel security, access control, audit and accountability, identification and authentication, and media protection, and the insider question is answered by the combination.
Which means a supplier can address it substantially without buying anything labelled for the purpose, and the entry on what is not required applies.
What a programme contains
Six things, only one of them technology
Access granted by role and reviewed. Separation of duties where the size of the organisation permits it. Records of who did what. A departure process that runs on the day. A channel for people to report concerns. And detection that produces a small number of signals worth looking at.
The first five are process and cost little. The sixth is where a product helps and it is the last one to reach for rather than the first.
The people question
Personnel security, briefly
The standard expects screening appropriate to the role and a process covering transfers and departures. What screening is appropriate depends on the work and, for some programmes, on requirements outside this standard entirely.
This is an employment law question as much as a security one and it is handled with advice rather than by policy download.
Proportion
Design for the common case
If the great majority of what you will encounter is error and convenience, the highest-value work is making the correct action easy and the incorrect one visible. That is the argument of the blog entry on how a control looks from the machine, arriving from a different direction.
A programme designed for the rare malicious case tends to produce controls people resent, which increases the common case.
Saying it out loud
Tell people what the programme assumes
That most of what it finds will be mistakes, that mistakes reported early are welcome, and that the point is to protect the contracts everybody's job depends on.
Stated once, publicly, this changes how the whole thing is received. Left unstated, people assume the dramatic reading, because that is what the words suggest.
The reporting channel
People notice things before systems do
A colleague behaving unusually, a contractor asking odd questions, a door propped open. Most of what is worth knowing arrives from a person, and only if there is somewhere to take it and a belief that something will happen.
The blog entry on unworkable controls describes the same channel serving a different purpose, which is an argument for having one rather than two.
Also
Elsewhere in insider risk
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.