Insider risk templates: which scenario, which prerequisite

This sheet compares Data theft by departing users, Data leaks by risky users, Data leaks by priority users, Security policy violations, Patient data misuse.

CriterionData theft by departing usersData leaks by risky usersData leaks by priority usersSecurity policy violationsPatient data misuse
DetectsExfiltration near resignation or end dates: SharePoint downloads, printing, copying to personal cloud storageData-leak activity from users showing disgruntlement, eg demotions, poor reviews, threatening messagesDLP-triggered leaks by users flagged as priority, scored with higher severity than the base templateUsers installing malware or disabling security features on their devicesUnauthorized access, modification, or export of patient records in an EMR system

The verdict, the full comparison, 4 rules and 4 traps are part of SC-401 access. Unlock SC-401.