AT.L2-3.2.3Insider Threat Awareness
Provide security awareness training on recognizing and reporting potential indicators of insider threat.
[a]
potential indicators associated with insider threats are identified; and[b]
security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.
Insider-threat indicators taught alongside a no-blame reporting path
Implementation
AO coverage. Addresses both Insider Threat Awareness objectives: identifying potential indicators and delivering training on recognizing and reporting them to managers and employees.
Identified indicators. The working group maintains a short, plain-language indicator list rather than a psychological profile: bulk download or printing of drawings outside a project need, requests for access that the person's work does not require, attempts to bypass media or egress controls, working unusual hours in the enclave without a project reason, unreported foreign travel or contacts tied to program work, expressions of intent to take material to a competitor, and disregard for handling rules after coaching. The list explicitly covers unintentional insiders — the well-meaning engineer who mails a drawing home to finish over the weekend.
Training content. Every employee and manager takes a dedicated insider-threat module annually, separate from general awareness so it is not diluted. It teaches the indicator list with short scenarios drawn from public case summaries, states plainly that reporting is about protecting both the company and the colleague, and walks through exactly what happens after a report.
Reporting path. Three channels: the person's manager, the ISSO directly, or an anonymous line that reaches the working group. Reports are acknowledged within one business day. Retaliation is a policy violation, and the training says so. Managers receive an additional segment on receiving a report without investigating on their own.
Triage. The working group — ISSO, HR, and legal — reviews every report. Technical corroboration uses existing audit data under a documented, HR-approved process; there is no ad-hoc surveillance of an individual on a manager's say-so.
Maintenance. Indicator list reviewed annually and after any relevant incident. Reporting volume and time-to-acknowledge are tracked; zero reports for a year is treated as a signal to test the channels, not as success.
Accepted gap. Subcontractor staff badged to our site take our module, but we cannot see indicators visible only inside their employer. Subcontract language requires their sponsor to notify us of a relevant personnel action, and their access is scoped to a single project area.
What the evidence looks like
- Indicator list with review date and working-group membership by role
- Insider-threat module content outline and annual completion report
- Reporting procedure describing all three channels and the acknowledgment commitment
- Working-group charter covering triage and the approval path for technical corroboration
- Subcontract clause requiring sponsor notification
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.