Insider threat program
Term · Cybersecurity · MLC-T-CYB-002166
1. A coordinated collection of capabilities authorized by the Department/Agency (D/A) that is organized to deter, detect, and mitigate the unauthorized disclosure of sensitive information.
2. A coordinated group of capabilities under centralized management that is organized to detect and prevent the unauthorized disclosure of sensitive information. At a minimum, for departments and agencies that handle classified information, an insider threat program shall consist of capabilities that provide access to information; centralized information integration, analysis, and response; employee insider threat awareness training; and the monitoring of user activity on government computers. For department and agencies that do not handle classified information, these can be employed effectively for safeguarding information that is unclassified but sensitive.
3. A coordinated collection of capabilities authorized by the organization and used to deter, detect, and mitigate the unauthorized disclosure of information.
| Identifier | MLC-T-CYB-002166 |
|---|---|
| Field | Cybersecurity |
| References | CNSSI 4009-2015 from CNSSD No. 504; NIST SP 800-53 Rev. 4 [Superseded] from Presidential Memorandum, National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs; NIST SP 800-53 Rev. 5 from CNSSI 4009-2015 (Adapted), CNSSI 4009-2022 (Adapted); NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-002166",
"term": "Insider threat program",
"field": "Cybersecurity",
"definition": "1. A coordinated collection of capabilities authorized by the Department/Agency (D/A) that is organized to deter, detect, and mitigate the unauthorized disclosure of sensitive information.\n\n2. A coordinated group of capabilities under centralized management that is organized to detect and prevent the unauthorized disclosure of sensitive information. At a minimum, for departments and agencies that handle classified information, an insider threat program shall consist of capabilities that provide access to information; centralized information integration, analysis, and response; employee insider threat awareness training; and the monitoring of user activity on government computers. For department and agencies that do not handle classified information, these can be employed effectively for safeguarding information that is unclassified but sensitive.\n\n3. A coordinated collection of capabilities authorized by the organization and used to deter, detect, and mitigate the unauthorized disclosure of information.",
"references": [
"CNSSI 4009-2015 from CNSSD No. 504",
"NIST SP 800-53 Rev. 4 [Superseded] from Presidential Memorandum, National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs",
"NIST SP 800-53 Rev. 5 from CNSSI 4009-2015 (Adapted), CNSSI 4009-2022 (Adapted)",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/insider-threat-program/"
}
Record 2,157 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.