Insider risk templates: which scenario, which prerequisite
This sheet compares Data theft by departing users, Data leaks by risky users, Data leaks by priority users, Security policy violations, Patient data misuse.
| Criterion | Data theft by departing users | Data leaks by risky users | Data leaks by priority users | Security policy violations | Patient data misuse |
|---|---|---|---|---|---|
| Detects | Exfiltration near resignation or end dates: SharePoint downloads, printing, copying to personal cloud storage | Data-leak activity from users showing disgruntlement, eg demotions, poor reviews, threatening messages | DLP-triggered leaks by users flagged as priority, scored with higher severity than the base template | Users installing malware or disabling security features on their devices | Unauthorized access, modification, or export of patient records in an EMR system |
The verdict, the full comparison, 4 rules and 4 traps are part of SC-401 access. Unlock SC-401.