Skip to content
ControlVerdict
AT.L2-3.2.3addresses
AT.L2-3.2.3Insider Threat Awareness
Provide security awareness training on recognizing and reporting potential indicators of insider threat.
  • [a]

    potential indicators associated with insider threats are identified; and
  • [b]

    security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.

View full control

Insider-threat indicators taught alongside a no-blame reporting path

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Insider Threat Awareness objectives: identifying potential indicators and delivering training on recognizing and reporting them to managers and employees.

Identified indicators. The working group maintains a short, plain-language indicator list rather than a psychological profile: bulk download or printing of drawings outside a project need, requests for access that the person's work does not require, attempts to bypass media or egress controls, working unusual hours in the enclave without a project reason, unreported foreign travel or contacts tied to program work, expressions of intent to take material to a competitor, and disregard for handling rules after coaching. The list explicitly covers unintentional insiders — the well-meaning engineer who mails a drawing home to finish over the weekend.

Training content. Every employee and manager takes a dedicated insider-threat module annually, separate from general awareness so it is not diluted. It teaches the indicator list with short scenarios drawn from public case summaries, states plainly that reporting is about protecting both the company and the colleague, and walks through exactly what happens after a report.

Reporting path. Three channels: the person's manager, the ISSO directly, or an anonymous line that reaches the working group. Reports are acknowledged within one business day. Retaliation is a policy violation, and the training says so. Managers receive an additional segment on receiving a report without investigating on their own.

Triage. The working group — ISSO, HR, and legal — reviews every report. Technical corroboration uses existing audit data under a documented, HR-approved process; there is no ad-hoc surveillance of an individual on a manager's say-so.

Maintenance. Indicator list reviewed annually and after any relevant incident. Reporting volume and time-to-acknowledge are tracked; zero reports for a year is treated as a signal to test the channels, not as success.

Accepted gap. Subcontractor staff badged to our site take our module, but we cannot see indicators visible only inside their employer. Subcontract language requires their sponsor to notify us of a relevant personnel action, and their access is scoped to a single project area.

What the evidence looks like

  • Indicator list with review date and working-group membership by role
  • Insider-threat module content outline and annual completion report
  • Reporting procedure describing all three channels and the acknowledgment commitment
  • Working-group charter covering triage and the approval path for technical corroboration
  • Subcontract clause requiring sponsor notification

Environment

Engineering services firm, ~90 people with a heavy subcontractor mix and hybrid work. Historically nobody reported concerns about colleagues, which the last assessment flagged as a cultural risk.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.