INSIDER RISK BODY
OF KNOWLEDGE
™
Insider Risk Body Of Knowledge
™
A Public Knowledge Resource for Insider Risk and Insider Threat
Practitioners
The NITSIG is pleased to announce the Insider Risk Body of Knowledge
™ (BoK
™),
a public knowledge resource created and maintained by ITMG®, in
collaboration with the NITSIG, to help practitioners, leaders, and
cross-functional stakeholders better understand insider risk and insider
threat management.
Official Source Of Record: Insider Risk Body Of Knowledge
™
https://itmg.co/insider-risk-body-of-knowledge/
Related Resource: Insider Risk Capability Framework
™ (IRCF
™)
https://itmg.co/insider-risk-capability-framework/
NITSIG Adoption Statement
The BoK
™ has been reviewed, approved, and adopted by the NITSIG
as a public insider risk management resource. ITMG® remains the official
source of record for the current version, updates, supporting materials,
and related implementation resources.
Why The BoK
™ Matters & Is Needed
The insider risk discipline is complex. It includes security
monitoring, employee trust, data protection, investigations, access
governance, legal and privacy requirements, workforce lifecycle risk,
behavioral indicators, training, reporting, and executive
decision-making. These topics are often discussed separately, which can
make it difficult for organizations to develop a common vocabulary or a
coordinated program model.
The Insider Risk BoK
™
was created to help address that challenge. It
provides a structured, educational resource for understanding insider
risk concepts, terminology, use cases, tools, procedures, standards,
metrics, stakeholder roles, events, case studies, templates, checklists,
and training pathways.
The BoK
™
helps shift the conversation from isolated alerts to broader
exposure management. It encourages organizations to ask better questions
about trusted access, sensitive assets, legal and privacy
considerations, functional roles, program metrics, and executive
reporting.
Relationship To The IRCF
™
The Insider Risk Body of Knowledge
™
is designed to complement the
Insider Risk Capability Framework
™
(IRCF)
™. The IRCF
™
provides the canonical
capability model for insider risk program maturity. It defines the major
capability areas organizations should understand, assess, and improve.
The BoK
™
provides the educational and applied knowledge layer. It
explains the concepts, terms, use cases, tools, procedures, standards,
metrics, stakeholder roles, and examples that help practitioners
understand and apply the broader discipline.
In simple terms: The IRCF
™
defines the capability model. The BoK
™
helps
practitioners understand the discipline behind the model. Together, the
IRCF
™
and BoK
™
help organizations move from fragmented insider threat
activity toward structured insider risk capability and exposure
management.
What The BoK
™ Covers
The Insider Risk BoK
™
is organized into knowledge hubs that allow
readers to explore the discipline from multiple angles. The NITSIG
provides this page as a high-level synopsis. Readers should visit ITMG®
for the full hub content and current updates.
Foundations - Introductory concepts that explain insider risk,
insider threat, trusted access, exposure management, employee
monitoring, program development, and why alert-only programs often fall
short.
Glossary - Plain-language definitions of key insider risk and
insider threat terms, roles, controls, metrics, investigation concepts,
and program concepts.
Use Cases - Applied scenarios such as leaver risk, data
exfiltration, privileged user misuse, third-party risk, compromised
insiders, negligent behavior, and AI-enabled data leakage.
Tools - Category-level explanations of technology used in insider
risk programs, including monitoring, analytics, DLP, SIEM, IAM, PAM,
case management, and exposure-management platforms.
Procedures - High-level procedural guidance for governance,
assessment, monitoring, triage, investigation, data protection,
escalation, reporting, and program improvement.
Standards - Educational alignment to public standards,
frameworks, and guidance relevant to insider risk, security, privacy,
compliance, access control, monitoring, and program governance.
Laws & Regulations - Educational context for legal and regulatory
considerations that may affect employee monitoring, privacy, data
handling, investigations, trade secrets, and workforce-related risk
management.
Metrics & KPIs - Examples of capability, exposure, confidence,
operational, investigation, control, and executive reporting metrics
that can help organizations evaluate program performance and
improvement.
Personas - Stakeholder-specific guidance for executives, security
analysts, investigators, HR, legal, privacy, compliance, IAM, data
protection teams, contractors, privileged users, leavers, and other
relevant groups.
Events & Case Studies - Public case studies and event-based
lessons that translate real-world insider incidents into practical
program observations without sensationalizing the events.
Templates & Checklists - Foundational previews, outlines, and
checklists that help organizations organize program artifacts,
governance structures, investigation considerations, and assessment
questions.
Training - Learning paths and professional education pathways for
practitioners, program leaders, executives, and cross-functional
stakeholders.
How Practitioners Can Use The BoK
™
The BoK
™
can be used as a starting point for education, program
planning, team alignment, stakeholder briefings, training development,
and capability improvement discussions.
New practitioners can use it to learn the language of insider risk.
Program managers can use it to orient stakeholders and identify areas
that require deeper review. Executives can use it to better understand
how insider risk connects to business exposure, not just security
operations. Legal, privacy, HR, and compliance teams can use it to
understand how their roles fit within a responsible program.
The BoK
™
is not a substitute for legal advice, compliance determinations,
internal policy review, or formal assessment. It is an educational
resource intended to help organizations ask better questions, align
stakeholders, and mature their understanding of insider risk.
Source Of Record
NITSIG is providing this page as a high-level introduction for the
insider threat and insider risk community. The official and most current
version is maintained by ITMG®.
Readers should visit ITMG® for the full Insider Risk Body of Knowledge
™,
current content, supporting materials, updates, and related
implementation resources.
View the full resource at ITMG®:
https://itmg.co/insider-risk-body-of-knowledge/
Attribution
The Insider Risk Body of Knowledge
™
(BoK
™) is a public insider risk
management resource created and maintained by ITMG®, in collaboration
with NITSIG. Following a review by the NITSIG, the BoK
™
has been approved
and adopted by the NITSIG as a public insider risk management resource
for the insider threat and insider risk community. ITMG® remains the
official source of record for the current version, updates, supporting
materials, and related implementation resources.