Start the process of implementing insider threat controls in your organization by classifying critical information by
confidentiality, integrity and availability with associated impact ratings. NIST SP 800-60 provides sample information categories and
impact definitions.
Data Type
Confidentiality
Integrity
Availability
Trade
Secrets
High
High
Medium
Human
Resources
High
Medium
Low
Financial
High
High
Medium
Now that your data has been defined and classified by CIA
rating, identify system boundaries. Boundaries should include systems, data
flow, networks, people and hard copy printouts.
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.