INSIDER RISK
CAPABILITY FRAMEWORK
™
Insider Risk Capability Framework
™
A Public Reference Model for Insider Risk Program Capability
The National Insider Threat Special Interest Group (NITSIG) is pleased
to announce the Insider Risk Capability Framework
™
(IRCF ™),
a public reference model created and maintained by ITMG®, in
collaboration with the NITSIG, to help organizations better understand,
assess, communicate, and mature the capabilities required to manage
insider risk.
Official Source Of Record : Insider Risk Capability Framework
™
https://itmg.co/insider-risk-capability-framework/
Related Resource: Insider Risk Body of Knowledge
™
(BoK
™)
https://itmg.co/insider-risk-body-of-knowledge/
NITSIG Adoption Statement
The IRCF
™
has been reviewed, approved, and adopted by the NITSIG as a public
insider risk management framework. ITMG® remains the official source of
record for the current version, updates, supporting materials, and
related implementation resources
Why the IRCF
™
Matters And Is Needed
The insider risk discipline has evolved significantly. Many
organizations now operate monitoring tools, investigation processes,
security controls, compliance programs, and employee awareness
initiatives. Yet even mature organizations often struggle to answer
basic leadership questions:
• What insider risk capabilities do we actually have?
• Where are we most exposed?
• Which gaps should be prioritized first?
• Are our capabilities improving?
• Can we prove progress to executives, auditors, regulators, and
oversight stakeholders?
The IRCF
™
was developed to help close that capability clarity gap. It gives
insider risk leaders, security teams, legal, HR, privacy, compliance,
investigations, data protection, identity and access management, and
executive stakeholders a shared language for understanding what a
complete insider risk capability should include.
From Reactive Threat Detection To Proactive Risk Capability
Insider risk is not owned by one team, one tool, or one
function. It exists across people, access, data, systems, business
processes, third parties, culture, and governance. As a result,
effective insider risk management requires more than alert review or
incident response. It requires a defensible operating model that
connects prevention, detection, analysis, investigation, mitigation,
oversight, reporting, and continuous improvement.
Rather than asking only, “What alerts did we detect?” the framework
encourages programs to ask broader and more strategic questions about
governance, monitoring, analysis, investigations, access, data
protection, personnel assurance, oversight, training, risk management,
and reporting.
Framework Structure
The IRCF
™
organizes insider risk program capability into ten major components:
1. Governance - Authority, ownership, decision rights, escalation
paths, and executive oversight.
2. Monitoring - Responsible observation, signal collection,
alerting, and monitoring governance across digital, physical,
behavioral, access, and data environments.
3. Analysis - The ability to interpret, correlate, enrich, and
convert fragmented information into actionable insider risk insight.
4. Investigation - Processes, roles, evidence practices,
documentation standards, and escalation pathways for consistent and
defensible investigations.
5. Identity & Access Management - Controls related to identity,
entitlement, privilege, access lifecycle, and role-based access
exposure.
6. Data Protection - Capabilities to identify, protect, monitor,
and govern sensitive data that could create insider risk exposure.
7. Personnel Assurance - Workforce lifecycle, suitability,
behavioral, role-based, and contextual factors that can influence
insider risk.
8. Oversight & Compliance - Auditability, policy alignment, legal
and privacy boundaries, compliance mechanisms, and responsible program
oversight.
9. Training - Awareness, role-based education, leadership
enablement, reporting pathways, and program communications.
10. Risk Management & Reporting - The ability to connect
findings, gaps, recommendations, roadmap progress, metrics, and
executive reporting into a coherent exposure-management model.
These components are intended to help organizations understand the major
building blocks of insider risk program capability. The full IRCF
™
provides additional context, maturity indicators, common gaps, standards
alignment, and implementation considerations.
How Organizations Can Use the IRCF
™
Organizations building a new program can use the IRCF
™
to understand the core capability areas that should be considered from
the beginning. Organizations with existing insider threat or insider
risk programs can use the framework to evaluate whether current
activities are coordinated, mature, and supported by evidence.
The framework can also support internal conversations among security,
HR, legal, privacy, compliance, audit, data protection, IAM, and
business stakeholders. Because insider risk cuts across functional
boundaries, a shared capability model can help reduce confusion, clarify
ownership, and improve prioritization.
Source Of Record
NITSIG is providing this page as a high-level introduction for
the insider threat and insider risk community. The official and most
current version is maintained by ITMG®.
Readers should visit ITMG® for the full Insider Risk Capability
Framework
™,
current content, supporting materials, updates, and related
implementation resources.
https://itmg.co/insider-risk-capability-framework/
Attribution
The Insider Risk Capability Framework
™
(IRCF
™)
is a public insider risk management framework created and maintained by
ITMG®, in collaboration with the NITSIG. Following a review by the
NITSIG, the IRCF
™
has been approved and adopted by the NITSIG as a public insider risk
management framework for the insider threat and insider risk community.
ITMG® remains the official source of record for the current version,
updates, supporting materials, and related implementation resources.