SFPC Insider Threat Awareness 2 — Questions and Answers
Question 1: What is an 'insider threat' in the security context?
- A threat from someone outside the organization
- A security risk posed by individuals within an organization who have authorized access but misuse it (Correct answer)
- A threat that only affects insider trading
- A risk from contractors who have never been cleared
Correct answer: A security risk posed by individuals within an organization who have authorized access but misuse it
An insider threat is a security risk posed by persons who have authorized access to organizational resources and who use that access—wittingly or unwittingly—in a way that harms the organization.
An insider threat is a malicious or negligent act by a current or former employee, contractor, or business partner who has or had authorized access to an organization's network, system, or data. Insider threats can be intentional (malicious insiders seeking to cause harm) or unintentional (negligent insiders who make mistakes that expose the organization to risk).
Question 2: What behavioral indicator may suggest an employee is becoming a potential insider threat?
- Consistently arriving on time
- Expressing unexplained financial concerns or discussing financial difficulties (Correct answer)
- Participating in company social events
- Requesting additional training opportunities
Correct answer: Expressing unexplained financial concerns or discussing financial difficulties
Unexplained or unusual financial concerns can be a behavioral indicator of potential insider threat, particularly if the individual has access to valuable information or assets.
Behavioral indicators of potential insider threats include unexplained financial changes (new wealth or financial difficulties), disgruntlement with the organization, expressed sympathy for adversaries, unusual work hours or remote access patterns, attempts to access information beyond job requirements, and discussions of grievances. No single indicator is conclusive, but patterns of indicators warrant closer attention and reporting.
Question 3: What is the 'Continuous Evaluation' (CE) program in the context of insider threats?
- Annual performance reviews for security personnel
- A program that continuously monitors the security posture of information systems
- A program that performs ongoing automated record checks on cleared personnel to identify potentially disqualifying information (Correct answer)
- A monthly check-in process with cleared personnel
Correct answer: A program that performs ongoing automated record checks on cleared personnel to identify potentially disqualifying information
Continuous Evaluation uses automated record checks to continuously monitor cleared personnel for potentially disqualifying information, rather than relying only on periodic reinvestigations.
The Continuous Evaluation (CE) program is a personnel security initiative that uses automated record checks across multiple government and commercial databases to continuously monitor cleared individuals for behaviors or activities that may be disqualifying. CE supplements periodic reinvestigations by providing near-real-time notification of potentially concerning activities such as arrests, financial issues, or foreign travel.
Question 4: What is the role of a 'User Activity Monitoring' (UAM) system in insider threat programs?
- Tracking employee social media activity outside work
- Monitoring employee computer and network activity to detect potentially malicious or unauthorized actions (Correct answer)
- Measuring employee productivity levels
- Monitoring employee health and wellness metrics
Correct answer: Monitoring employee computer and network activity to detect potentially malicious or unauthorized actions
UAM systems monitor the activities of users with access to sensitive systems to detect anomalous or unauthorized behavior that may indicate an insider threat.
User Activity Monitoring (UAM) is a technical capability that records and analyzes the activities of users with access to sensitive information systems. UAM can detect potentially malicious behaviors such as unauthorized data exfiltration, excessive access to sensitive files, unusual login times, or use of unauthorized applications. UAM is an important component of a comprehensive insider threat program.
Question 5: What does the 'MICE' acronym represent in the context of insider threat motivations?
- Methods, Indicators, Counterintelligence, Evidence
- Money, Ideology, Coercion/Compromise, Ego (Correct answer)
- Management, Investigation, Compliance, Enforcement
- Monitoring, Intelligence, Collection, Exploitation
Correct answer: Money, Ideology, Coercion/Compromise, Ego
MICE represents the four primary motivations for insider threats: Money (financial gain), Ideology (beliefs or grievances), Coercion/Compromise (being blackmailed or coerced), and Ego (pride or revenge).
MICE is a framework used in security training to describe the primary motivations that may drive an individual to become an insider threat. Money refers to financial incentives for selling information. Ideology refers to strongly held beliefs that may lead someone to act against their organization. Coercion or Compromise means being blackmailed or coerced into actions. Ego refers to pride, recognition, or revenge motivations.
Question 6: What action should employees take when they observe suspicious behavior by a colleague?
- Confront the colleague directly
- Report the behavior through established reporting mechanisms to the insider threat program or security officer (Correct answer)
- Post about it on the company intranet
- Ignore it unless they are certain it is a security violation
Correct answer: Report the behavior through established reporting mechanisms to the insider threat program or security officer
Employees should report suspicious behavior through established channels, such as the insider threat reporting hotline or directly to the security officer, rather than confronting the colleague.
When an employee observes suspicious behavior that may indicate an insider threat, the appropriate action is to report the information through established reporting channels, such as a security officer, the insider threat program manager, or an anonymous hotline. Direct confrontation could compromise investigations and potentially create safety risks. Training should emphasize that reporting is not a betrayal but a responsibility.
What is an 'insider threat' in the security context?