Insider Threat Awareness Flashcards

1
Q

DoD Directive 5205.16 defines Insider as:

A

Any person with authorized access to DoD resources by virtue of employment, volunteer activities, or contractual relationship with DoD. This can include employees, former employees, consultants, and anyone with access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The National Insider Threat Task Force (NITTF) defines an insider threat as:

A

The threat that an insider will use his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of department resources or capabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the five main NITTF categories of insider threat?

A

Leaks: Intentional or unauthorized disclosure of classified or proprietary information to person or org who does not have a need–to–know.

Spills: Unintentional transfer of classified or proprietary information to unaccredited or unauthorized systems, individuals, applications or media (doesn’t have to be intentional–is most common)

Espionage: The unauthorized transmittal of classified or proprietary information to a competitor, foreign nation or entity with the intent to harm.

Sabotage: To deliberately destroy, damage, or destruct, especially for political or military advantage. Although sabotage is often conducted for political or military reasons, other motivations can include personal disgruntlement.

Targeted violence: Any form of violence that is directed at an individual or group, for a specific reason. Not a random act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Categories of Targeted Violence

A
Active shooter
domestic violence
harassment
hostile work environment
sexual assault
stalking
threats/threatening behavior
workplace bullying/violence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Insider Threat Vulnerabilities

A

Disgruntlement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Terms for reporting requirements

A

Contact: Any association, connection, or communication with another individual occurring in person or via any form of technology

Foreign national: any person who is not a U.S citizen, or in some instances, possesses dual citizenship. Legal permanent residents are foreign nationals

Personal Info: Identifying info which is not commonly known or readily and publicly available, such as name, address, or occupation. Information which a foreign national could use to exploit vulnerabilities for CI or security reasons.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly