CISA Publish Updated Insider Threat Mitigation Guide

The Cybersecurity and Infrastructure Security Agency (CISA) has released a newly updated Insider Threat Mitigation Guide. This effort continues CISA’s commitment to raising awareness of risks posed by insider threats to the Nation’s critical infrastructure and empowering our partners with effective mitigation strategies for these threats.
Originally published by CISA in late 2020, the Guide has been updated in response to frequent partner requests for expanded guidance on this critical topic. The Guide provides critical infrastructure stakeholders with practical information about insider threats, their various forms, and recommended practices for developing or improving mitigation programs. An established program serves to protect key assets, prevent violence, minimize unintentional incidents, reduce losses related to revenue or intellectual property, safeguard sensitive data, and save lives.
Key updates in the Guide include:
• New case studies, statistics, and improvements designed to enhance the original content, streamline information delivery, and ensure continued relevance
• Expanded insights on emerging workplace trends such as increased hybrid and remote work, advances in Artificial Intelligence (AI), and other pertinent considerations relating to insider threats
• Access to newly released CISA resources supporting preparedness and early risk detection
What’s Inside:
- Types of Insider Threats: Learn about intentional and unintentional insider threats in an organization.
- Detection Strategies: Identify behaviors and indicators of potential insider incidents.
- Assessment Guidelines: Best practices for insider threat assessments to inform mitigation strategies.
- Threat Management: Intervention best practices balancing organizational protection and individual care.
- Mitigation Program: Steps to create or improve an insider threat mitigation program.
Resources: Tools, resources, and a glossary for program development.
CISA published the updated guide to coincide with National Insider Threat Awareness Month (NITAM). Each September, NITAM brings together security professionals from government and industry to promote detection, assessment, and proactive management of insider threats.

Leave a Reply