IMO Insider Threat Toolkit
As discussed within the 2024 August newsletter, the IMO Insider Threat toolkit provides some guidance with respect to different things that can be done to mitigate insider threats. A degree of caution is recommended and those thinking about implementing the controls recommended in that package should do so with the assistance of competent practitioners that have experience in this domain.
Privacy-related issues, understanding what constitutes suspect behaviour in multicultural environments, and similar challenges can become difficult waters for organizations that blindly implement certain kinds of controls. Additionally, the imposition of these kinds of controls into environments where “pressure is the norm” could possibly lead to challenges depending on how staff interpret the appearance of such controls.
Finally, while the focus on security controls provides good guidance, several routines support those controls. Asset management, inventory control, appropriate human resources and contracting processes all contribute to the weave that becomes an effective insider threat program.