Assessing Continuous Evaluation Approaches for Insider Threats How Can the Security Posture of the U.S
Total Page:16
File Type:pdf, Size:1020Kb
Assessing Continuous Evaluation Approaches for Insider Threats How Can the Security Posture of the U.S. Departments and Agencies Be Improved? David Luckey, David Stebbins, Rebeca Orrie, Erin Rebhan, Sunny D. Bhatt, Sina Beaghley C O R P O R A T I O N For more information on this publication, visit www.rand.org/t/RR2684 Library of Congress Cataloging-in-Publication Data is available for this publication. ISBN: 978-1-9774-0194-6 Published by the RAND Corporation, Santa Monica, Calif. © Copyright 2019 RAND Corporation R® is a registered trademark. Cover: Photo by Andrea Danti / stock.adobe.com. Limited Print and Electronic Distribution Rights This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited. Permission is given to duplicate this document for personal use only, as long as it is unaltered and complete. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial use. For information on reprint and linking permissions, please visit www.rand.org/pubs/permissions. The RAND Corporation is a research organization that develops solutions to public policy challenges to help make communities throughout the world safer and more secure, healthier and more prosperous. RAND is nonprofit, nonpartisan, and committed to the public interest. RAND’s publications do not necessarily reflect the opinions of its research clients and sponsors. Support RAND Make a tax-deductible charitable contribution at www.rand.org/giving/contribute www.rand.org Preface This exploratory project examines various continuous evaluation (CE) approaches to detecting insider threats that are available to the U.S. government and assesses the rel- evance of these approaches to the challenges posed by such insider threats. Our report defines CE as a vetting and adjudication process to review on an ongoing basis the background of an individual who has been determined eligible for access to classified information or to hold a sensitive position at any time during the period of eligibility. There are potential benefits from CE in effectiveness and cost over the current method of granting security clearances to personnel based on periodic reinvestigation and read- judication. CE, however, has yet to be widely adopted. Over the previous decade, trusted insiders have caused extreme harm to the United States and its citizens. The scope of threats of future attacks by those who have been deemed trustworthy could range from modest to catastrophic. What capabilities exist to combat insider threats? What aspects of CE are being implemented to address insider threats? What are some costs and benefits of CE? What could be considered in the future? In this report, we will explore these and other questions. This report should be of interest to the U.S. Department of Defense, the U.S. Intelligence Community, and all other public and private organizations with cleared populations or that face a higher risk of threat from insiders. This research was spon- sored by the Office of the Secretary of Defense and conducted within the Cyber and Intelligence Policy Center of the RAND National Defense Research Institute (NDRI), a federally funded research and development center (FFRDC) sponsored by the Office of the Secretary of Defense, the Joint Staff, the Unified Combatant Commands, the Navy, the Marine Corps, the defense agencies, and the Intelligence Community. For more information on the Cyber and Intelligence Policy Center, see www.rand.org/ nsrd/ndri/centers/intel or contact the director (contact information is provided on the webpage). iii Contents Preface ................................................................................................. iii Figures and Tables ...................................................................................vii Summary .............................................................................................. ix Acknowledgments ................................................................................. xvii Abbreviations ........................................................................................ xix CHAPTER ONE Introduction ........................................................................................... 1 The Traditional Security Clearance Process ........................................................ 1 Methodology ........................................................................................... 3 CHAPTER TWO Insider Threat and Continuous Evaluation Defined ........................................... 7 Insider Threat .......................................................................................... 7 Continuous Evaluation ...............................................................................11 Findings and Recommendations ....................................................................14 CHAPTER THREE Background: Addressing Insider Threats .......................................................17 When Did the United States First Consider Insider Threats and Continuous Evaluation? ........................................................................................17 Are Insider Threats Uniform Across Industry? ....................................................19 Does the U.S. Government Consider Security Negligence a Form of Insider Threat? ...... 20 Findings and Recommendations ................................................................... 22 CHAPTER FOUR What Capabilities Exist to Combat Insider Threats? ........................................ 23 What Are Some Best Practices to Combat Insider Threats? .................................... 23 Could Behavioral Measures Be Used to Combat Insider Threats? ............................. 28 How Are Technical Measures Used to Combat Insider Threats? ...............................31 Findings and Recommendations ....................................................................33 v vi Assessing Continuous Evaluation Approaches for Insider Threats CHAPTER FIVE How Is Continuous Evaluation Implemented Today? ........................................37 How Do Different Sectors Address Insider Threats and Continuous Evaluation Issues? ....37 How Successful Has Continuous Evaluation Been So Far? ..................................... 40 What Are Some Costs and Benefits of Continuous Evaluation? ................................47 What Is Not Continuous Evaluation? ..............................................................49 What Are Some Challenges to Implementing Continuous Evaluation? ....................... 50 Findings and Recommendations ....................................................................51 CHAPTER SIX Conclusion ............................................................................................55 References .............................................................................................57 Figures and Tables Figures 3.1. Five Types of Insiders ....................................................................21 5.1. Estimated Costs of Continuous Evaluation Versus the Current Review System over Time for One Employee................................................. 48 Tables 1.1. Primary Documents for Insider Threat and Continuous Evaluation Standards .................................................................................. 4 2.1. Examples of Different Definitions of Insider Threat by Sector ....................10 2.2. National Insider Threat Task Force Categories of Continuous Evaluation .......13 2.3. GAO Report Findings by Government Entity .......................................14 4.1. Summary of Key Behavioral Models Adapted to Combat Insider Threats .......29 5.1. Descriptions and Results of ACES Pilot Projects ................................... 42 vii Summary The threat from insiders is not new; the fact that there are costs due to national secu- rity and intelligence leaks have been known since the founding of the United States, and the tragedy of physical violence that has been conducted by coworkers is nearly incomprehensible. Over the past decade in particular, trusted U.S. government insiders have murdered fellow workers and physically and psychologically injured others. Insid- ers have also caused what some government experts have estimated as billions of dollars and irreparable damage to the United States through the unauthorized disclosure of national security information.1 U.S. alliances have been negatively affected, domestic and international trust in U.S. institutions has been reduced, and some current and potential federal employees have lost confidence in the ability of the very government they serve to provide for their security.2 The trustworthiness of those who guard the secrets of the United States should be beyond reproach. The United States needs a process and systems that can assess trustworthiness as required. The current security clearance process is based on periodic and aperiodic investigations and adjudication, and this process and the systems that support it are decades old. Technology has advanced significantly since this system was put in place; an updated, improved system and process could capitalize on these tech- nological advancements. The threat from insiders is very real, and this insider threat puts the United States and U.S. government employees at risk. U.S. department and agency data and the physical