Start the process of implementing insider threat controls in your organization by classifying critical information by confidentiality, integrity and availability with associated impact ratings. NIST SP 800-60
Requires Free Membership to View
SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!
Michael S. Mimoso, Editorial Director| Data Type | Confidentiality | Integrity | Availability |
| Trade Secrets | High | High | Medium |
| Human Resources | High | Medium | Low |
| Financial | High | High | Medium |
Now that your data has been defined and classified by CIA rating, identify system boundaries. Boundaries should include systems, data flow, networks, people and hard copy printouts.
INSIDER THREAT MANAGEMENT GUIDE
Introduction: Insider threat management guide
Baseline management and control
Implementation of baseline control
Risk management audit
Risk management references
This was first published in August 2006