NATIONAL INSIDER THREAT SPECIAL INTEREST GROUP - NITSIG

 

INSIDER RISK BODY OF KNOWLEDGE

 

 

Insider Risk Body Of Knowledge
A Public Knowledge Resource for Insider Risk and Insider Threat Practitioners

The NITSIG is pleased to announce the Insider Risk Body of Knowledge
(BoK ), a public knowledge resource created and maintained by ITMG®, in collaboration with the NITSIG, to help practitioners, leaders, and cross-functional stakeholders better understand insider risk and insider threat management.

 

Official Source Of Record: Insider Risk Body Of Knowledge
https://itmg.co/insider-risk-body-of-knowledge/

Related Resource: Insider Risk Capability Framework
(IRCF )
https://itmg.co/insider-risk-capability-framework/


NITSIG Adoption Statement
The BoK
has been reviewed, approved, and adopted by the NITSIG as a public insider risk management resource. ITMG® remains the official source of record for the current version, updates, supporting materials, and related implementation resources.
 


Why The BoK
Matters & Is Needed
The insider risk discipline is complex. It includes security monitoring, employee trust, data protection, investigations, access governance, legal and privacy requirements, workforce lifecycle risk, behavioral indicators, training, reporting, and executive decision-making. These topics are often discussed separately, which can make it difficult for organizations to develop a common vocabulary or a coordinated program model.

The Insider Risk BoK
was created to help address that challenge. It provides a structured, educational resource for understanding insider risk concepts, terminology, use cases, tools, procedures, standards, metrics, stakeholder roles, events, case studies, templates, checklists, and training pathways.

The BoK
helps shift the conversation from isolated alerts to broader exposure management. It encourages organizations to ask better questions about trusted access, sensitive assets, legal and privacy considerations, functional roles, program metrics, and executive reporting.

Relationship To The IRCF

The Insider Risk Body of Knowledge
is designed to complement the Insider Risk Capability Framework (IRCF) . The IRCF provides the canonical capability model for insider risk program maturity. It defines the major capability areas organizations should understand, assess, and improve.

The BoK
provides the educational and applied knowledge layer. It explains the concepts, terms, use cases, tools, procedures, standards, metrics, stakeholder roles, and examples that help practitioners understand and apply the broader discipline.

In simple terms: The IRCF
defines the capability model. The BoK helps practitioners understand the discipline behind the model. Together, the IRCF and BoK help organizations move from fragmented insider threat activity toward structured insider risk capability and exposure management.


What The BoK
Covers
The Insider Risk BoK
is organized into knowledge hubs that allow readers to explore the discipline from multiple angles. The NITSIG provides this page as a high-level synopsis. Readers should visit ITMG® for the full hub content and current updates.

Foundations - Introductory concepts that explain insider risk, insider threat, trusted access, exposure management, employee monitoring, program development, and why alert-only programs often fall short.

Glossary - Plain-language definitions of key insider risk and insider threat terms, roles, controls, metrics, investigation concepts, and program concepts.

Use Cases - Applied scenarios such as leaver risk, data exfiltration, privileged user misuse, third-party risk, compromised insiders, negligent behavior, and AI-enabled data leakage.

Tools - Category-level explanations of technology used in insider risk programs, including monitoring, analytics, DLP, SIEM, IAM, PAM, case management, and exposure-management platforms.

Procedures - High-level procedural guidance for governance, assessment, monitoring, triage, investigation, data protection, escalation, reporting, and program improvement.

Standards - Educational alignment to public standards, frameworks, and guidance relevant to insider risk, security, privacy, compliance, access control, monitoring, and program governance.

Laws & Regulations - Educational context for legal and regulatory considerations that may affect employee monitoring, privacy, data handling, investigations, trade secrets, and workforce-related risk management.

Metrics & KPIs - Examples of capability, exposure, confidence, operational, investigation, control, and executive reporting metrics that can help organizations evaluate program performance and improvement.

Personas
- Stakeholder-specific guidance for executives, security analysts, investigators, HR, legal, privacy, compliance, IAM, data protection teams, contractors, privileged users, leavers, and other relevant groups.

Events & Case Studies - Public case studies and event-based lessons that translate real-world insider incidents into practical program observations without sensationalizing the events.

Templates & Checklists - Foundational previews, outlines, and checklists that help organizations organize program artifacts, governance structures, investigation considerations, and assessment questions.

Training - Learning paths and professional education pathways for practitioners, program leaders, executives, and cross-functional stakeholders.


How Practitioners Can Use The BoK

The BoK
can be used as a starting point for education, program planning, team alignment, stakeholder briefings, training development, and capability improvement discussions.


New practitioners can use it to learn the language of insider risk. Program managers can use it to orient stakeholders and identify areas that require deeper review. Executives can use it to better understand how insider risk connects to business exposure, not just security operations. Legal, privacy, HR, and compliance teams can use it to understand how their roles fit within a responsible program.


The BoK
is not a substitute for legal advice, compliance determinations, internal policy review, or formal assessment. It is an educational resource intended to help organizations ask better questions, align stakeholders, and mature their understanding of insider risk.


Source Of Record
NITSIG is providing this page as a high-level introduction for the insider threat and insider risk community. The official and most current version is maintained by ITMG®.


Readers should visit ITMG® for the full Insider Risk Body of Knowledge
, current content, supporting materials, updates, and related implementation resources.
View the full resource at ITMG®: https://itmg.co/insider-risk-body-of-knowledge/


Attribution
The Insider Risk Body of Knowledge
(BoK ) is a public insider risk management resource created and maintained by ITMG®, in collaboration with NITSIG. Following a review by the NITSIG, the BoK has been approved and adopted by the NITSIG as a public insider risk management resource for the insider threat and insider risk community. ITMG® remains the official source of record for the current version, updates, supporting materials, and related implementation resources.


 

 

Copyright © 2021 - National Insider Threat Special Interest Group ™ - All Rights Reserved - Legal Notice