# 32 CFR § 2004.24: Insider threat program

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24

## Section

- **Citation:** 32 CFR § 2004.24
- **Heading:** Insider threat program
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** September 22, 2026
- **Source:** Publisher's official text
- **Location:** Title 32—National Defense > Subtitle B—Other Regulations Relating to National Defense > CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION > PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) > Subpart B—Administration

## Text

(a) Responsible CSAs oversee and analyze entity activity to ensure entities implement an insider threat program in accordance with the National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs (via requirements in the NISPOM or its equivalent) and guidance from the CSA. CSA oversight responsibilities include, but are not limited to:
(1) Verifying that entities appoint insider threat program SOs;
(2) Requiring entities to monitor, report, and review insider threat program activities and response actions in accordance with the provisions set forth in the NISPOM (or equivalent);
(3) Providing entities with access to data relevant to insider threat program activities and applicable reporting requirements and procedures;
(4) Providing entities with a designated means to report insider threat-related activity; and
(5) Advising entities on appropriate insider threat training for entity employees eligible for access to classified information.
(b) CSAs share with other CSAs any insider threat information reported to them by entities, as lawful and appropriate.

## Nearby sections

- [32 CFR § 2004.1 § 2004.1 Purpose and scope.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.1.md)
- [32 CFR § 2004.4 § 2004.4 Definitions that apply to this part.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.4.md)
- [32 CFR § 2004.10 § 2004.10 Responsibilities of the Director, Information Security Oversight Office (ISOO).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10.md)
- [32 CFR § 2004.11 § 2004.11 CSA and agency implementing regulations, internal rules, or guidelines.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.11.md)
- [32 CFR § 2004.12 § 2004.12 ISOO review of agency NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12.md)
- [32 CFR § 2004.20 § 2004.20 National Industrial Security Program Executive Agent and Operating Manual.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.20.md)
- [32 CFR § 2004.22 § 2004.22 Agency responsibilities.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.22.md)
- [32 CFR § 2004.24 § 2004.24 Insider threat program.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24.md)
- [32 CFR § 2004.26 § 2004.26 Reviews of entity NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.26.md)
- [32 CFR § 2004.28 § 2004.28 Cost reports.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28.md)
- [32 CFR § 2004.30 § 2004.30 Security classification requirements and guidance.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.30.md)
- [32 CFR § 2004.32 § 2004.32 Determining entity eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.32.md)
- [32 CFR § 2004.34 § 2004.34 Foreign ownership, control, or influence (FOCI).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.34.md)
- [32 CFR § 2004.36 § 2004.36 Determining entity employee eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.36.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24. Check the current official text before relying on it. Not legal advice.
