Requirement 0051 (Part Two: Risk, section 7.3 Countering Foreign Interference and Espionage; applies to All entities; dated 31 October 2024; retained from Release 2025): An insider threat program is implemented by entities that manage Baseline to Positive Vetting security clearance subjects, to manage the risk of insider threat in the entity. The program covers governance and planning, personnel security, culture and training, access controls, physical and ICT controls and audit, and review, reporting and response; TS-PA sponsors need a program meeting the TS-PA Standard.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.