Developing Evidence-Based Requirements and Content for Workforce Insider Risk Training, Awareness, and Behavior Change Campaigns – IN PROGRESS
Government and critical infrastructure industry organizations are mandated to deploy workforce insider risk training, awareness, and/or behavior change campaigns. However, there are no requirements for the content of those campaigns. Insider Risk Programs are generating ad-hoc, in-house content against no set requirements, and failing to leverage the science of behavior, attitude, and intention change. In absence of those requirements and human sciences, organizations are forced to implement campaigns primarily on anecdote and good ideas.
To help, MITRE has two active efforts. First, the team will research and create an evidence-based initial draft of content requirements for effective insider risk training, awareness, and behavior change campaigns. Second, the team will develop example training, awareness, and behavior change campaign content for deployment in government and critical infrastructure industry Insider Threat/Risk Programs. Moreover, MITRE will create a methodology to evaluate the relevance, usability, and effectiveness of those campaigns. These efforts will help government and critical infrastructure industry deploy insider risk training, awareness, and behavior change campaigns more consistently, efficiently, (i.e., better value for time and money), and effectively (e.g., demonstrated impact on attitudes, intentions, and behaviors).