They cover a mix of insider actions (espionage, embezzlement, sabotage, fraud, IP and R&D theft), program development and management issues, and related technical and organizational topics such as risk indicators, supply chain risk, and cybersecurity.
They present a step-by-step path for developing an insider threat program that emphasizes management and employee engagement, and that explicitly addresses ethical, legal, and privacy concerns throughout program design and operation.
They describe tactics for collecting, correlating, and visualizing potential risk indicators into monitoring systems, and they outline mitigation strategies focused on interrupting or limiting an insider’s harmful actions.
At least one description ties supply chain risk and cybersecurity directly to insider threat, treating those areas as related concerns to address within protection strategies.
They emphasize building effective awareness programs, transforming user attitudes and behavior, and making staff awareness a fundamental part of security efforts.