Establishing the Insider Threat Program Plan
This article addresses establishment of the Insider Threat Program Plan. The article is derived from the Self Inspection Handbook for NISP Contractors , and uses the format to walk through the self-inspection criteria. We begin the topic question, the NISPOM reference, an explanation of requirements, and finally how to inspect compliance. Topic Question(s): Has the company developed and implemented an insider threat program plan endorsed by the ITPSO? Do you have a written program plan that has been self-certified to DSS as current and implemented? EVIDENCE: Provide the policy, internal guidelines, and procedures. If you do not have an insider threat program established, do you have an implementation plan, roadmap, or milestones for establishing your program? EVIDENCE: Provide the implementation plan or milestones way ahead. NISPOM Reference(s): 1-202a Discussion: Once the Insider Threat Program Senior Official (ITPSO) is designated, the Celared Defense Contractor (CDC) enterprise c...