§ 2004.24 Insider threat program.

FederalRegulations

Ask Donna

How this section applies to your facts.

Title 32—National Defense > Subtitle B—Other Regulations Relating to National Defense > CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION > PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) > Subpart B—Administration

This text was captured on Sep 22, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

(a) Responsible CSAs oversee and analyze entity activity to ensure entities implement an insider threat program in accordance with the National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs (via requirements in the NISPOM or its equivalent) and guidance from the CSA. CSA oversight responsibilities include, but are not limited to:

(1) Verifying that entities appoint insider threat program SOs;

(2) Requiring entities to monitor, report, and review insider threat program activities and response actions in accordance with the provisions set forth in the NISPOM (or equivalent);

(3) Providing entities with access to data relevant to insider threat program activities and applicable reporting requirements and procedures;

(4) Providing entities with a designated means to report insider threat-related activity; and

(5) Advising entities on appropriate insider threat training for entity employees eligible for access to classified information.

(b) CSAs share with other CSAs any insider threat information reported to them by entities, as lawful and appropriate.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.