Skip to content
ControlVerdict
AT.L2-3.2.3CMMC Level 2Level 2

Insider Threat Awareness

Practice statement

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.2.3.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    potential indicators associated with insider threats are identified; and

    1 example covers this

  2. [b]

    security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AT.L2-3.2.3Insider Threat Awareness
    Provide security awareness training on recognizing and reporting potential indicators of insider threat.
    • [a]

      potential indicators associated with insider threats are identified; and
    • [b]

      security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.

    Insider-threat indicators taught alongside a no-blame reporting path

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Insider Threat Awareness objectives: identifying potential indicators and delivering training on recognizing and reporting them to managers and employees.

    Identified indicators. The working group maintains a short, plain-language indicator list rather than a psychological profile: bulk download or printing of drawings outside a project need, requests for access that the person's work does not require, attempts to bypass media or egress controls, working unusual hours in the enclave without a project reason, unreported foreign travel or contacts tied to program work, expressions of intent to take material to a competitor, and disregard for handling rules after coaching. The list explicitly covers unintentional insiders — the well-meaning engineer who mails a drawing home to finish over the weekend.

    Training content. Every employee and manager takes a dedicated insider-threat module annually, separate from general awareness so it is not diluted. It teaches the indicator list with short scenarios drawn from public case summaries, states plainly that reporting is about protecting both the company and the colleague, and walks through exactly what happens after a report.

    Reporting path. Three channels: the person's manager, the ISSO directly, or an anonymous line that reaches the working group. Reports are acknowledged within one business day. Retaliation is a policy violation, and the training says so. Managers receive an additional segment on receiving a report without investigating on their own.

    Triage. The working group — ISSO, HR, and legal — reviews every report. Technical corroboration uses existing audit data under a documented, HR-approved process; there is no ad-hoc surveillance of an individual on a manager's say-so.

    Maintenance. Indicator list reviewed annually and after any relevant incident. Reporting volume and time-to-acknowledge are tracked; zero reports for a year is treated as a signal to test the channels, not as success.

    Accepted gap. Subcontractor staff badged to our site take our module, but we cannot see indicators visible only inside their employer. Subcontract language requires their sponsor to notify us of a relevant personnel action, and their access is scoped to a single project area.

    What the evidence looks like

    • Indicator list with review date and working-group membership by role
    • Insider-threat module content outline and annual completion report
    • Reporting procedure describing all three channels and the acknowledgment commitment
    • Working-group charter covering triage and the approval path for technical corroboration
    • Subcontract clause requiring sponsor notification

    Environment

    Engineering services firm, ~90 people with a heavy subcontractor mix and hybrid work. Historically nobody reported concerns about colleagues, which the last assessment flagged as a cultural risk.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.