NATIONAL INSIDER THREAT SPECIAL INTEREST GROUP - NITSIG

 

 INSIDER RISK CAPABILITY FRAMEWORK
 

 

Insider Risk Capability Framework

A Public Reference Model for Insider Risk Program Capability

The National Insider Threat Special Interest Group (NITSIG) is pleased to announce the Insider Risk Capability Framework
(IRCF), a public reference model created and maintained by ITMG®, in collaboration with the NITSIG, to help organizations better understand, assess, communicate, and mature the capabilities required to manage insider risk.

Official Source Of Record : Insider Risk Capability Framework

https://itmg.co/insider-risk-capability-framework/

Related Resource: Insider Risk Body of Knowledge
(BoK )
https://itmg.co/insider-risk-body-of-knowledge/


NITSIG Adoption Statement
The IRCF
has been reviewed, approved, and adopted by the NITSIG as a public insider risk management framework. ITMG® remains the official source of record for the current version, updates, supporting materials, and related implementation resources


Why the IRCF
Matters And Is Needed
The insider risk discipline has evolved significantly. Many organizations now operate monitoring tools, investigation processes, security controls, compliance programs, and employee awareness initiatives. Yet even mature organizations often struggle to answer basic leadership questions:
• What insider risk capabilities do we actually have?
• Where are we most exposed?
• Which gaps should be prioritized first?
• Are our capabilities improving?
• Can we prove progress to executives, auditors, regulators, and oversight stakeholders?

The IRCF
was developed to help close that capability clarity gap. It gives insider risk leaders, security teams, legal, HR, privacy, compliance, investigations, data protection, identity and access management, and executive stakeholders a shared language for understanding what a complete insider risk capability should include.


From Reactive Threat Detection To Proactive Risk Capability
Insider risk is not owned by one team, one tool, or one function. It exists across people, access, data, systems, business processes, third parties, culture, and governance. As a result, effective insider risk management requires more than alert review or incident response. It requires a defensible operating model that connects prevention, detection, analysis, investigation, mitigation, oversight, reporting, and continuous improvement.

Rather than asking only, “What alerts did we detect?” the framework encourages programs to ask broader and more strategic questions about governance, monitoring, analysis, investigations, access, data protection, personnel assurance, oversight, training, risk management, and reporting.


Framework Structure
The IRCF
organizes insider risk program capability into ten major components:
1. Governance - Authority, ownership, decision rights, escalation paths, and executive oversight.


2. Monitoring - Responsible observation, signal collection, alerting, and monitoring governance across digital, physical, behavioral, access, and data environments.


3. Analysis - The ability to interpret, correlate, enrich, and convert fragmented information into actionable insider risk insight.


4. Investigation - Processes, roles, evidence practices, documentation standards, and escalation pathways for consistent and defensible investigations.


5. Identity & Access Management - Controls related to identity, entitlement, privilege, access lifecycle, and role-based access exposure.


6. Data Protection - Capabilities to identify, protect, monitor, and govern sensitive data that could create insider risk exposure.


7. Personnel Assurance - Workforce lifecycle, suitability, behavioral, role-based, and contextual factors that can influence insider risk.


8. Oversight & Compliance - Auditability, policy alignment, legal and privacy boundaries, compliance mechanisms, and responsible program oversight.


9. Training - Awareness, role-based education, leadership enablement, reporting pathways, and program communications.


10. Risk Management & Reporting - The ability to connect findings, gaps, recommendations, roadmap progress, metrics, and executive reporting into a coherent exposure-management model.

These components are intended to help organizations understand the major building blocks of insider risk program capability. The full IRCF
provides additional context, maturity indicators, common gaps, standards alignment, and implementation considerations.


How Organizations Can Use the IRCF

Organizations building a new program can use the IRCF to understand the core capability areas that should be considered from the beginning. Organizations with existing insider threat or insider risk programs can use the framework to evaluate whether current activities are coordinated, mature, and supported by evidence.

The framework can also support internal conversations among security, HR, legal, privacy, compliance, audit, data protection, IAM, and business stakeholders. Because insider risk cuts across functional boundaries, a shared capability model can help reduce confusion, clarify ownership, and improve prioritization.


Source Of Record
NITSIG is providing this page as a high-level introduction for the insider threat and insider risk community. The official and most current version is maintained by ITMG®.


Readers should visit ITMG® for the full Insider Risk Capability Framework
, current content, supporting materials, updates, and related implementation resources.
https://itmg.co/insider-risk-capability-framework/


Attribution
The Insider Risk Capability Framework
(IRCF ) is a public insider risk management framework created and maintained by ITMG®, in collaboration with the NITSIG. Following a review by the NITSIG, the IRCF has been approved and adopted by the NITSIG as a public insider risk management framework for the insider threat and insider risk community. ITMG® remains the official source of record for the current version, updates, supporting materials, and related implementation resources.
 

 

Copyright © 2021 - National Insider Threat Special Interest Group ™ - All Rights Reserved - Legal Notice