Skip to content

Insider Threat

What is Insider Threat?

A security risk that originates from within the organisation, typically from current or former employees, contractors, or business partners who have inside information concerning security practices, data, and computer systems.

Information Security

Each of these is named in at least one of the same controls as insider threat. The number is how many controls name both.

What the standards actually require on insider threat

Requirements naming insider threat across 6 standards, quoted from the control text.

Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;

FAA-CSA-Personnel · Personnel Security Training and Insider Threat

Develop and maintain an insider threat programme to deter, detect and respond to threats originating from individuals with authorised access, integrating personnel security, behavioural indicators, technical monitoring and reporting channels.

TSA-PSG-17 · Insider threat programme

Conduct background screening for personnel with access to treatment and SCADA systems and monitor for insider risk.

AWWA-G430-14 · Personnel Security and Insider Threat

Legal advice is sought regarding the development and implementation of an insider threat mitigation program.

ISM-1626 · Legal advice is sought regarding the development and implementation of an insider threat m
CMMC 2.01 control

Provide awareness training that teaches staff to recognize potential insider threat indicators and to report them.

AT.L2-3.2.3 · Insider Threat Awareness

Extends the insider threat programme to insiders introduced through the supply chain, including contractor and integrator personnel.

161R1-PM-12 · Insider Threat Program

Questions people ask about insider threat

What is Insider Threat?
A security risk that originates from within the organisation, typically from current or former employees, contractors, or business partners who have inside information concerning security practices, data, and computer systems.
Why is Insider Threat important for compliance?
Insider Threat is a key concept in Information Security. Understanding insider threat helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Insider Threat?
Insider Threat appears in the requirement text of FAA Cybersecurity Framework for Aviation, TSA Pipeline Security, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Australian Information Security Manual, CMMC 2.0. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Insider Threat?
Explore our compliance framework pages to see how insider threat applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Insider Threat applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.