Industry Validation
July 22, 2026
8 min read

NITSIG Reviews, Approves and Adopts the ITMG® IRCF® and Insider Risk BoK®

An important milestone for industry validation and the broader insider risk discipline as a key national special interest group approves two public reference standards.

The National Insider Threat Special Interest Group® (NITSIG®) has reviewed, approved, and adopted two foundational public resources created and maintained by ITMG®: the Insider Risk Capability Framework™ (IRCF™) and the Insider Risk Body of Knowledge™ (BoK™).

NITSIG adopted the IRCF™ as a public insider risk management framework and the Insider Risk BoK™ as a public insider risk management resource for the insider threat and insider risk community.

ITMG® remains the official source of record for the current versions, updates, supporting materials, and related implementation resources.

This is an important milestone for ITMG, but it is also an important step for the broader insider risk discipline.

Building a Common Model for Insider Risk

Insider risk programs are rarely built from one function, one tool, or one source of information. Responsibilities are distributed across security, legal, privacy, HR, compliance, investigations, identity and access management, data protection, physical security, business leadership, and other stakeholders.

Organizations may have many individual activities in place while still struggling to answer fundamental questions:

? What insider risk capabilities do we actually have?
? Where are our most important gaps?
? Which improvements should be prioritized?
? Who owns the decisions?
? Are our capabilities improving?
? Can we demonstrate progress to executives, board members, and auditors?

The IRCF™ and Insider Risk BoK™ were developed to help organizations answer those questions through a more consistent and practical model.

The Insider Risk Capability Framework™

The Insider Risk Capability Framework™ provides a common language for understanding, assessing, communicating, and improving insider risk program capability.

The framework organizes insider risk into ten connected components:

1. Governance
2. Monitoring
3. Analysis
4. Investigation
5. Identity & Access
6. Data Protection
7. Personnel Assurance
8. Oversight & Compliance
9. Training
10. Risk Management

These components help organizations look beyond isolated tools, alerts, policies, or investigations. They provide a broader view of whether the organization has the governance, processes, controls, evidence, accountability, and improvement mechanisms required to manage insider risk as an enterprise concern.

The framework is public, practitioner-informed, and maintained by ITMG®. It is designed to help organizations establish a common capability model without exposing proprietary assessment logic or treating the framework as a compliance certification.

NITSIG’s IRCF™ adoption statement confirms that the framework has been reviewed, approved, and adopted as a public insider risk management framework.

The Insider Risk Body of Knowledge™

The Insider Risk Body of Knowledge™ provides the educational and applied knowledge layer that complements the IRCF™.

The BoK™ brings together practical information across the insider risk discipline, including:

  • Foundational concepts and terminology
  • Insider risk and insider threat use cases
  • Technology and tool categories
  • Program procedures
  • Standards and guidance
  • Laws and regulatory considerations
  • Metrics and key performance indicators
  • Stakeholder personas

The purpose is not to prescribe one identical program for every organization. Insider risk programs must reflect their organization’s business, workforce, technology, legal obligations, privacy requirements, risk profile, and operating environment.

The BoK™ instead gives practitioners and leaders a structured place to learn the discipline, explore relevant topics, align stakeholders, and identify areas requiring more detailed assessment or implementation.

NITSIG’s Insider Risk BoK™ adoption statement confirms that the resource has been reviewed, approved, and adopted as a public insider risk management resource.

How the IRCF™ and BoK™ Work Together

The IRCF™ and Insider Risk BoK™ serve different but complementary purposes.

The IRCF™ defines the capability model. It helps organizations understand the major capabilities an effective insider risk program should be able to demonstrate, assess, and improve.

The Insider Risk BoK™ explains the broader discipline behind the model. It provides practical educational context around concepts, terminology, use cases, tools, procedures, standards, metrics, stakeholder roles, and implementation considerations.

"The IRCF™ defines the capabilities. The Insider Risk BoK™ helps practitioners understand and apply the discipline behind them. Together, the resources help organizations move from fragmented insider threat activities toward structured, coordinated, and defensible insider risk capability."

Why NITSIG Adoption Matters

External adoption matters because an industry framework becomes more useful when it creates a common point of reference beyond the organization that developed it.

NITSIG’s review, approval, and adoption provide external industry validation that the IRCF™ and Insider Risk BoK™ address a real need within the insider threat and insider risk community.

The adoption also helps reinforce several important principles:

1. Insider risk is broader than threat detection

Effective programs require coordinated capability across multiple organizational functions (legal, HR, security, privacy) rather than solely relying on cyber monitoring alerts.

2. Practitioners need both capability models and applied knowledge

Connecting structural capability assessments with a comprehensive educational and reference knowledge baseline accelerates organizational alignment.

3. Ownership and Source-of-Record responsibility must remain clear

Public resources advance the industry while preserving ITMG®'s role in continuously developing, updating, and holding the source-of-record versions.

NITSIG provides public adoption statements and high-level introductions to both resources. ITMG® remains the official source for the complete and current IRCF™ and Insider Risk BoK™ content.

A Foundation for Continued Industry Development

ITMG developed these resources to help create greater consistency in how organizations understand and manage insider risk.

The objective is not to claim that every program should look identical. The objective is to give organizations a stronger starting point, a shared vocabulary, and a structured way to evaluate whether their activities add up to a coherent and defensible capability.

The resources will continue to evolve as insider risk programs confront changes in technology, artificial intelligence, workforce models, third-party access, privacy expectations, regulatory obligations, and the ways sensitive information is accessed, transformed, and moved.

NITSIG’s adoption represents meaningful validation of that direction and an important opportunity to expand practitioner awareness and use of these public resources.

Explore the Adopted Resources

Use the direct paths below to access the official ITMG® public resources and review NITSIG's official statements of adoption:

ST

About the Author

Shawn M. Thompson, Esq.

Shawn M. Thompson, Esq. is the founder and CEO of ITMG, founder of RiskTKO, and creator of the Insider Risk Capability Framework and Insider Risk Body of Knowledge. A former FBI Assistant General Counsel, federal prosecutor, NSA Insider Threat Program Manager and Senior Special Agent, and Google Global Insider Risk Practice Lead, he has supported more than 300 insider risk engagements for over 100 Fortune 500 organizations.

Operationalize the NITSIG-Adopted Standards

Learn how RiskTKO® and ITMG's elite consulting teams can help you assess your current posture against the Insider Risk Capability Framework™ and build a defensible program.