Evaluating The Effectiveness Of Insider Threat Mitigation Systems

Year
2021
Author(s)
Sondra Spence - Sandia National Laboratories
Steven M. Horowitz - Sandia National Laboratories
Gregory Baum - Sandia National Laboratories
Joel Lewis - Lawrence Livermore National Laboratory
Thomas Edmunds - Lawrence Livermore National Laboratory
Claude "Russ" Clark - Y-12 National Security Complex
Tyler Cooperider - Y-12 National Security Complex
Mary Lin - Y-12 National Security Complex
File Attachment
a150.pdf1.44 MB
Abstract
Evaluating the Effectiveness of Insider Threat Mitigation Systems: Defending against insider threat is a topic of increasing concern to the international nuclear community. Nuclear facilities must be able to evaluate the effectiveness of insider threat mitigation strategies and understand how to use results to strengthen and integrate those mitigations into a robust program. With support from the NNSA’s Office of International Nuclear Security, Subject Matter Experts (SMEs) have developed a series of workshops that provide the foundational knowledge needed to build and sustain an Insider Threat Evaluation Program. This presentation defines a systematic method for evaluating insider threat program effectiveness using documentation, assumption validation, and preventive and protective mitigation measurement to determine program quality and efficacy. The presentation shows how a hypothetical facility is used to deliver a series of customized workshops which apply a site-specific, graded approach to nuclear security, as recommended by the IAEA. The workshops also engage stakeholders with different responsibilities, roles, and engagement levels in the overall evaluation program, which serves to increase understanding and communication, and ultimately enables a more robust and sustainable program.Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energys National Nuclear Security Administration under contract DE-NA0003525. OR [For abstract submissions where there is a character limit] SNL is managed and operated by NTESS under DOE NNSA contract DE-NA0003525 - SAND2021-1786 A