The National Insider Threat Special Interest Group® (NITSIG®) has reviewed, approved, and adopted two foundational public resources created and maintained by ITMG®: the Insider Risk Capability Framework™ (IRCF™) and the Insider Risk Body of Knowledge™ (BoK™).
NITSIG adopted the IRCF™ as a public insider risk management framework and the Insider Risk BoK™ as a public insider risk management resource for the insider threat and insider risk community.
ITMG® remains the official source of record for the current versions, updates, supporting materials, and related implementation resources.
This is an important milestone for ITMG, but it is also an important step for the broader insider risk discipline.
Building a Common Model for Insider Risk
Insider risk programs are rarely built from one function, one tool, or one source of information. Responsibilities are distributed across security, legal, privacy, HR, compliance, investigations, identity and access management, data protection, physical security, business leadership, and other stakeholders.
Organizations may have many individual activities in place while still struggling to answer fundamental questions:
The IRCF™ and Insider Risk BoK™ were developed to help organizations answer those questions through a more consistent and practical model.
The Insider Risk Capability Framework™
The Insider Risk Capability Framework™ provides a common language for understanding, assessing, communicating, and improving insider risk program capability.
The framework organizes insider risk into ten connected components:
These components help organizations look beyond isolated tools, alerts, policies, or investigations. They provide a broader view of whether the organization has the governance, processes, controls, evidence, accountability, and improvement mechanisms required to manage insider risk as an enterprise concern.
The framework is public, practitioner-informed, and maintained by ITMG®. It is designed to help organizations establish a common capability model without exposing proprietary assessment logic or treating the framework as a compliance certification.
NITSIG’s IRCF™ adoption statement confirms that the framework has been reviewed, approved, and adopted as a public insider risk management framework.
The Insider Risk Body of Knowledge™
The Insider Risk Body of Knowledge™ provides the educational and applied knowledge layer that complements the IRCF™.
The BoK™ brings together practical information across the insider risk discipline, including:
- Foundational concepts and terminology
- Insider risk and insider threat use cases
- Technology and tool categories
- Program procedures
- Standards and guidance
- Laws and regulatory considerations
- Metrics and key performance indicators
- Stakeholder personas
The purpose is not to prescribe one identical program for every organization. Insider risk programs must reflect their organization’s business, workforce, technology, legal obligations, privacy requirements, risk profile, and operating environment.
The BoK™ instead gives practitioners and leaders a structured place to learn the discipline, explore relevant topics, align stakeholders, and identify areas requiring more detailed assessment or implementation.
NITSIG’s Insider Risk BoK™ adoption statement confirms that the resource has been reviewed, approved, and adopted as a public insider risk management resource.
How the IRCF™ and BoK™ Work Together
The IRCF™ and Insider Risk BoK™ serve different but complementary purposes.
The IRCF™ defines the capability model. It helps organizations understand the major capabilities an effective insider risk program should be able to demonstrate, assess, and improve.
The Insider Risk BoK™ explains the broader discipline behind the model. It provides practical educational context around concepts, terminology, use cases, tools, procedures, standards, metrics, stakeholder roles, and implementation considerations.
"The IRCF™ defines the capabilities. The Insider Risk BoK™ helps practitioners understand and apply the discipline behind them. Together, the resources help organizations move from fragmented insider threat activities toward structured, coordinated, and defensible insider risk capability."
Why NITSIG Adoption Matters
External adoption matters because an industry framework becomes more useful when it creates a common point of reference beyond the organization that developed it.
NITSIG’s review, approval, and adoption provide external industry validation that the IRCF™ and Insider Risk BoK™ address a real need within the insider threat and insider risk community.
The adoption also helps reinforce several important principles:
1. Insider risk is broader than threat detection
Effective programs require coordinated capability across multiple organizational functions (legal, HR, security, privacy) rather than solely relying on cyber monitoring alerts.
2. Practitioners need both capability models and applied knowledge
Connecting structural capability assessments with a comprehensive educational and reference knowledge baseline accelerates organizational alignment.
3. Ownership and Source-of-Record responsibility must remain clear
Public resources advance the industry while preserving ITMG®'s role in continuously developing, updating, and holding the source-of-record versions.
NITSIG provides public adoption statements and high-level introductions to both resources. ITMG® remains the official source for the complete and current IRCF™ and Insider Risk BoK™ content.
A Foundation for Continued Industry Development
ITMG developed these resources to help create greater consistency in how organizations understand and manage insider risk.
The objective is not to claim that every program should look identical. The objective is to give organizations a stronger starting point, a shared vocabulary, and a structured way to evaluate whether their activities add up to a coherent and defensible capability.
The resources will continue to evolve as insider risk programs confront changes in technology, artificial intelligence, workforce models, third-party access, privacy expectations, regulatory obligations, and the ways sensitive information is accessed, transformed, and moved.
NITSIG’s adoption represents meaningful validation of that direction and an important opportunity to expand practitioner awareness and use of these public resources.
Explore the Adopted Resources
Use the direct paths below to access the official ITMG® public resources and review NITSIG's official statements of adoption:
Insider Risk Capability Framework™
Explore the complete framework, its ten components, maturity model, standards alignment, AI context, common gaps, and implementation guidance.
Insider Risk Body of Knowledge™
Explore public guidance covering insider risk concepts, use cases, tools, procedures, standards, laws, metrics, personas, case studies, templates, checklists, and training.