IR-4(6): Insider Threats
Implement an incident handling capability for incidents involving insider threats.
- Control Family: Incident Response
- Control Set: NIST Special Publication 800-53 Revision 5.2.0
Implement an incident handling capability for incidents involving insider threats.
Provide literacy training on recognizing and reporting potential indicators of insider threat.
Implement an insider threat program that includes a cross-discipline insider threat incident handling team.
Coordinate an incident handling capability for insider threats that includes the following organizational entities [Assignment: organization-defined entities].
The organization includes security awareness training on recognizing and reporting potential indicators of insider threat.
The organization implements an insider threat program that includes a cross-discipline insider threat incident handling team.
The organization implements incident handling capability for insider threats.
The organization coordinates incident handling capability for insider threats across [Assignment: organization-defined components or elements of the organization].
Potential indicators and possible precursors of insider threat include behaviors such as: inordinate, long-term job dissatisfaction; attempts to gain access to information that is not required for job performance; unexplained access to financial resources; bullying or sexual harassment of fellow employees; workplace violence; and other serious violations of the policies, procedures, directives, rules, or practices … Continue reading ""
Provide security literacy training to system users: As part of initial training for new users and [Assignment: organization-defined frequency] thereafter, When required by system changes or following [Assignment: organization-defined events], and On recognizing and reporting indicators of insider threat, social engineering, and social mining. Update security literacy training content [Assignment: organization-defined frequency] and following [Assignment: … Continue reading ""
Include as part of control assessments, [Assignment: organization-defined specialized assessment frequency], [Assignment: announced, unannounced], [Assignment (one or more): in-depth monitoring, security instrumentation, automated security test cases, vulnerability scanning, malicious user testing, insider threat assessment, performance and load testing, data leakage or data loss assessment, [Assignment: organization-defined other forms of assessment] ].
Enforce dual authorization for [Assignment: organization-defined privileged commands and/or other actions].
Employ [Assignment: organization-defined techniques] for [Assignment: organization-defined data storage objects] to detect and protect against unauthorized data mining.
[csf.tools Note: Subcategories do not have detailed descriptions.]
The organization includes as part of security control assessments, [Assignment: organization-defined frequency], [Selection: announced; unannounced], [Selection (one or more): in-depth monitoring; vulnerability scanning; malicious user testing; insider threat assessment; performance/load testing; [Assignment: organization-defined other forms of security assessment]].
Log the execution of privileged functions.
Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
Alert [Assignment: organization-defined personnel or roles] when the following system-generated indications of compromise or potential compromise occur: [Assignment: organization-defined compromise indicators].
Alert [Assignment: organization-defined personnel or roles] using [Assignment: organization-defined automated mechanisms] when the following indications of inappropriate or unusual activities with security or privacy implications occur: [Assignment: organization-defined activities that trigger alerts].
Prevent non-privileged users from executing privileged functions. Log the execution of privileged functions.
[csf.tools Note: Subcategories do not have detailed descriptions.]
Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [Assignment: organization-defined systems or system components].
The information system audits the execution of privileged functions.
The organization employs automated mechanisms to alert security personnel of the following inappropriate or unusual activities with security implications: [Assignment: organization-defined activities that trigger alerts].
The organization correlates information from nontechnical sources with audit information to enhance organization-wide situational awareness.