PM-12 Insider Threat Program

Program Management

Description

Implement an insider threat program that includes a cross-discipline insider threat incident handling team.

Supplemental Guidance

Organizations that handle classified information are required, under Executive Order 13587 and the National Insider Threat Policy, to establish insider threat programs. The standards and guidelines that apply to insider threat programs in classified environments can also be employed effectively to improve the security of controlled unclassified information in non-national security systems. Insider threat programs include controls to detect and prevent malicious insider activity through the centralized integration and analysis of both technical and nontechnical information to identify potential insider threat concerns.

Changes from Rev 4

No significant changes from Rev 4.

Compliance Mappings

RBI CSF

Annex1.23

DNB Good Practice

DNB.15.2DNB.8.1DNB.8.2DNB.8.3DNB.9.3

CBE CSF

CD-1

CBN CSF

Part9

BoG CISD

CISD-XIIICISD-XV

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.SA

FFIEC IS

II.AII.A.1III.A

ECB CROE

CROE.2.5.1CROE.2.7.2

CMMC 2.0

IR

NERC CIP

CIP-014-3

Lloyd's Minimum Standards

MS2.1

FDA Cybersecurity Guidance

TM-1

Basel SCO60

SCO60.55