Control Statement
The organization shall define, and be able to execute, a rights-respecting process for resolving an indication of insider risk, with a stated disposition period.
Purpose. To be able to resolve an indication proportionately and lawfully, so that the organization is neither unable to act nor acting without safeguards.
Discussion
This control is written around resolving an *indication*, not around monitoring a population, and the distinction is the whole design. A process that begins with an indication and proceeds under defined safeguards is insider risk management; a capability that continuously scores individuals for propensity is workforce surveillance, and it corrodes exactly the cooperation that makes the rest of this family work. The rights safeguards are therefore assessed as part of the control rather than treated as an external constraint: legal and privacy review of the process, defined authority to initiate, minimum-necessary access to personal information, a disposition period that prevents indefinite open suspicion, and a route by which a closed indication leaves no residue against the person.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Whether the process is documented, approved, and rehearsed
- Mean time from indication to disposition, against the stated period
- Proportion of cases with recorded legal and human-resources involvement before any action affecting an individual
- Number of indications resolved as unfounded, and whether records were handled accordingly
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- WF-2 Privileged Human RegisterPrivileged human register
- Outside the frameworkLegal, human-resources, privacy and union or works-council requirements
Produces
- CG-3 Rules of EngagementAuthority levels for actions affecting an individual
- WF-5 Separation and Revocation TempoSuspension pathway into revocation
- CG-4 Findings DispositionCase dispositions recorded
- EN-3 Evidence PreservationLegal and privacy determinations bounding what may be held
Activities
- L2Define the process for resolving an indication of insider risk.
- L2Name the process owner and the authority required to initiate.
- L2State the disposition period within which an indication must be resolved.
- L3Obtain legal and privacy review of the process before it is used, and record the review.
- L3Define the minimum information the process may access at each stage, so escalation of access follows escalation of evidence rather than preceding it.
- L3Define how a closed indication is recorded, including that an unsubstantiated indication leaves no adverse residue against the individual.
- L3Define the route for referral to human resources, counsel or law enforcement, and the point at which the security function ceases to lead.
- L3Flag open indications exceeding the disposition period.
- L4Measure disposition times against the stated period, and the proportion of indications closed as unsubstantiated — a rate near zero suggests the threshold to initiate is set too high, and a rate near one that it is too low.
- L4Test the process against a documented scenario rather than waiting for a real indication to discover it does not work.
- L5Review closed indications for the conditions that produced them and address those conditions, since most substantiated insider events have precursors that were organizational rather than individual.
Measurement
Percentage of indications dispositioned within the stated period.
Proportion of indications closed as unsubstantiated, trended.
Evidence and Assessment
Documented process with legal and privacy review; disposition record for closed indications; scenario test record.
Examine the process for rights safeguards and approval; test that closed indications met the stated period; test whether access escalation followed evidence escalation; examine whether unsubstantiated closures left residue.
Related Guidance
- PM-12
- AU-6(9)
- PS-8
- DE.CM-03
- GV.RR-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.15
Terrain It Is Named On
- T7WorkforceInsider risk position — including the requirement to state what is deliberately not monitored.
Artifacts It Stands On
- producesInsider risk positionThe stated position on insider risk: what may be done, by whom, under what legal, privacy and labor-relations constraints, and how a case is dispositioned.
- consumesPrivileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.