GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-012 Insider Threat Programme

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An insider threat programme exists with a named owner and a documented procedure approved by the security, human resources and legal functions. The procedure lists the behavioural and technical indicators that are monitored, the threshold at which an indicator is escalated, the escalation path across those functions, the investigation procedure and how evidence is handled. A confidential reporting channel is available to personnel and is published where they will find it. Indicator reviews and escalated cases are recorded. A cross-functional review of the programme is recorded at defined intervals.

Rationale

An insider already holds the access the perimeter was built to control, so detection depends on behaviour and not on authorisation. Behaviour is only interpretable when security, human resources and legal see it together. The approval by all three functions is the structural test: a programme owned by security alone has no route to the employment context that makes an indicator meaningful and no authority to act on it. The evidence handling clause matters because an insider case usually ends in a disciplinary or legal process where how the evidence was gathered decides whether it can be used. Issued in S4 when GOV-027 was re-homed to HRS (CQ-072, ADR-007, ADR-033). GOV-008 assesses the fraud scenarios this programme responds to, GOV-009 holds segregation of duties, DAT-017 the data loss detection the technical indicators draw on and HRS-006 the disciplinary process. A good-faith report about the organisation itself and the published protection for the person who makes it are HRS-009; the confidential channel here takes a concern about a person.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (4)

HIPAA-164.308.a.1.ii.CSanction Policyinformative
5.3Segregation of dutiesinformative
PM-12Insider Threat Programfull
CC3.3COSO Principle 8: Assesses Fraud Riskinformative

Evidence (2)

policydocumentmanual

Insider threat programme policy or procedure defining detection processes, escalation paths, investigation procedures, and reporting channels.

Example: Insider Threat Programme Policy or Procedure (Confluence), approved by CISO, HR, and Legal, covering: behavioural and technical indicators to monitor, escalation path (security → HR → Legal), investigation procedure, and the reporting channel available to staff.

Test: Request the insider threat programme procedure. Verify: (1) it is approved by the security, human resources and legal functions, or by at least two of them with the third recorded as consulted, (2) the behavioural and technical indicators monitored are listed, (3) the threshold at which an indicator is escalated is stated, (4) the escalation path names the functions and the roles it passes through, (5) the investigation procedure and the handling of evidence are described, (6) a confidential reporting channel is described and the procedure says where it is published, (7) a named programme owner is identified, (8) the procedure carries an approval date within the defined interval.

reportdocumentmanual

Insider threat programme activity report or log showing the programme is operational: indicators reviewed, cases escalated, or tests conducted.

Example: Insider threat quarterly review report (Confluence / PDF) or case management log (ServiceNow / legal hold system), showing: the review period, number of alerts or indicators reviewed, number escalated to investigation, and disposition, with names or case IDs redacted as appropriate.

Test: Request the most recent insider threat programme activity report or case log summary. Verify: (1) it covers the most recent defined review period, (2) at least one category of indicator monitoring is evidenced as active, (3) a cross-functional review involving security and either human resources or legal is recorded, (4) escalated cases show the threshold that triggered them and their disposition, (5) the named programme owner matches the procedure.

Questions (2)

boolean

Does your organisation have a documented insider threat programme with a named owner?

The procedure is the artefact and the owner is the part most often missing. A collection of detection tooling with no procedure, no escalation path and nobody accountable for the programme does not meet the control; Q2 captures which capabilities are in place.

multi

Which of the following insider threat capabilities are in place?

Behavioural analytics or data loss alertingPrivileged access monitoring for high-risk accountsA documented escalation path from security to human resources and legalA confidential reporting channel available to personnelA cross-functional review recorded at defined intervalsA documented investigation procedure covering the handling of evidenceNone of the above

A detection capability without the escalation path and the investigation procedure produces alerts nobody can act on. The last item is what decides whether the evidence gathered survives a disciplinary or legal process.