Table 9.

Insider threat scenario

DomainSub-metric
si
wi
siwi
Procedural alignmentEscalation path followed4520
IRP referenced during incident3515
Deviations justified4416
Operational executionContainment-action timing3412
Task coverage248
Execution accuracy4520
Infrastructure integrationTool-usage effectiveness3412
Tool alignment to IRP236
Inter-tool visibility339
Coordination and commsRole clarity4520
Decision flow3515
Communication logging3412
Post-incident follow-throughRoot-cause analysis339
Lessons learned236
IRP updated post-simulation133
TotalsΣwi = 60Σ siwi = 183
Source(s): Authors’ own work

or Create an Account

Close Modal
Close Modal