3.2.3: Provide security awareness training on recognizing and reporting potential indicators of insider threat

Potential indicators and possible precursors of insider threat include behaviors such as: inordinate, long-term job dissatisfaction; attempts to gain access to information that is not required for job performance; unexplained access to financial resources; bullying or sexual harassment of fellow employees; workplace violence; and other serious violations of the policies, procedures, directives, rules, or practices … Continue reading ""

03.02.01: Literacy Training and Awareness

Provide security literacy training to system users: As part of initial training for new users and [Assignment: organization-defined frequency] thereafter, When required by system changes or following [Assignment: organization-defined events], and On recognizing and reporting indicators of insider threat, social engineering, and social mining. Update security literacy training content [Assignment: organization-defined frequency] and following [Assignment: … Continue reading ""

CA-2(2): Specialized Assessments

Include as part of control assessments, [Assignment: organization-defined specialized assessment frequency], [Assignment: announced, unannounced], [Assignment (one or more): in-depth monitoring, security instrumentation, automated security test cases, vulnerability scanning, malicious user testing, insider threat assessment, performance and load testing, data leakage or data loss assessment, [Assignment: organization-defined other forms of assessment] ].

CA-2(2): Specialized Assessments

The organization includes as part of security control assessments, [Assignment: organization-defined frequency], [Selection: announced; unannounced], [Selection (one or more): in-depth monitoring; vulnerability scanning; malicious user testing; insider threat assessment; performance/load testing; [Assignment: organization-defined other forms of security assessment]].