unified
UC-GOV-37 — Operate insider-threat and threat-awareness programs
Implement an insider threat program that includes a cross-discipline insider threat incident handling team and defined indicators, reporting channels, and response procedures, together with a threat awareness program that shares current threat information across the organization, including with leadership and security personnel. Review the effectiveness of both programs at defined intervals and adjust them to the evolving threat environment.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- detective
- category
- administrative
Details
- unified_id
- UC-GOV-37
- title
- Operate insider-threat and threat-awareness programs
- statement
- Implement an insider threat program that includes a cross-discipline insider threat incident handling team and defined indicators, reporting channels, and response procedures, together with a threat awareness program that shares current threat information across the organization, including with leadership and security personnel. Review the effectiveness of both programs at defined intervals and adjust them to the evolving threat environment.
- domain
- Governance, Policy & Oversight
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-12
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-16
- coverage
- partial
- delta
- PM-16 requires cross-organization (inter-organizational) threat-intelligence sharing, not only internal dissemination
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-37 — Operate insider-threat and threat-awareness programs mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- primary
- rationale
- An insider-threat program with defined indicators, reporting channels, and response detects and deters insider theft and fraud.
- UC-GOV-37 — Operate insider-threat and threat-awareness programs maps_to PM-12 — Insider Threat Program
- framework
- nist-800-53
- control_id
- PM-12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Threat Intelligence & Insider Threat Program operates UC-GOV-37 — Operate insider-threat and threat-awareness programs
- UC-GOV-37 — Operate insider-threat and threat-awareness programs maps_to PM-16 — Threat Awareness Program
- framework
- nist-800-53
- control_id
- PM-16
- coverage
- partial
- delta
- PM-16 requires cross-organization (inter-organizational) threat-intelligence sharing, not only internal dissemination
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-37 — Operate insider-threat and threat-awareness programs mitigates Unauthorized activity — rogue trading, position mismarking, concealment
- strength
- related
- rationale
- Insider-threat indicators and monitoring add a detective layer over concealed rogue activity.