Skip to main content

Insider Threat Solution Requirements Checklist

The technical evaluation process for new security technology can be time-consuming but it’s critically important. All stakeholders must be aligned on what success looks like. This includes the business problems that are to be solved, the technical capabilities needed to solve them, as well as the time, money and effort required to administer a solution.


We’ve helped you get started. Review this checklist to speed up your evaluation process and build stakeholder consensus on the requirements for purchasing an insider threat solution. Add any custom requirements to the empty lines.


Use Case Requirements

The high-level specifications that will enable you to manage insider threats. Use case requirements should be agreed upon by all project stakeholders.

Code42 icon for high-risk employees

  1. Delivers company-wide visibility into data risk caused by end-users
  2. Delivers visibility into the insider threat activity of individual users 
  3. Detects file exfiltration 
  4. Detects file infiltration 
  5. Detects file deletion and sabotage 
  6. Supports insider threat investigation and incident response
  7. Monitors user activity with respect for employee privacy
  8. [Your additional requirement here]


Technical Requirements

The technical specifications required to successfully meet your use cases. Technical requirements should be set and evaluated by security analysts and architects. 

  1. Offers an interface that is easy to use and navigate
  2. Works without inhibiting employee productivity
  3. Monitors file activity that takes place on employee computers, regardless of network
  4. Monitors the creation, deletion, modification and movement of filesCode42 icon for mitigating Insider Risk
  5. Detects removable media, cloud/web app, web upload and printing activity
  6. Detects file sharing from a corporate cloud service to untrusted domains
  7. Detects file attachments from a corporate email service to untrusted domains
  8. Detects file deletions and provides recovery of those deleted files  
  9. Offers customized monitoring for specific groups of users
  10. Monitors employees during departures and layoffs 
  11. Monitors high-risk employees (contractors, privileged access, flight risks, etc)
  12. Prioritizes the file activity that requires investigation
  13. Identifies activity that takes place outside of a user’s typical hours
  14. Provides a historical view of user file activity
  15. Monitors files without requiring them to be tagged or classified 
  16. Provides access to file contents for investigation
  17. Enables alerts to be customized and sent to other systems
  18. Logs file metadata, including file name, path, size and MD5/SHA256 hash
  19. Logs event information, including date, time, activity type and description of threat vectors
  20. Logs user information, including username, title, department, manager, and location 
  21. Supports organization-wide search by criteria, such as file name or hash 
  22. Supports insider threat and intellectual property lawsuits via legal hold and eDiscovery features or integrations
  23. [Your additional requirement here]


Architectural Requirements

The specifications that will support a smooth deployment and integration with your existing IT and security investments. These should be established by security and IT stakeholders. 

  1. Solution is cloud-based
  2. Cloud deployment can support federal and compliance requirements, if needed
  3. Open API is available for scripting and custom integrations
  4. Agent works well on all Mac, Windows and Linux operating systems
  5. Agent can be mass deployed and silently installed
  6. Agent testing reveals minimal endpoint impact  
  7. Agent does not require VPN
  8. New agent releases can be tested prior to company-wide rollout 
  9. Pre-built integrations are available for technologies, including SSO, SIEM and SOAR
  10. [Your additional requirement here]


Vendor Requirements

Your expectations for how a vendor will support you as a customer. These requirements are particularly important to security, procurement and legal stakeholders.

  1. Supplies evidence of corporate data security, privacy and compliance
  2. Demonstrates a proven ability to support global customersCode42 icon for shadow IT detection
  3. Provides introductions to customer references
  4. Assigns a dedicated account manager to customers
  5. Demonstrates a history of executing to roadmap commitments
  6. Offers opportunities to participate in advisory and early access programs
  7. Demonstrates a proven ability to quickly deploy new customers
  8. Offers consultative services
  9. Provides knowledgeable and friendly support that is not outsourced
  10. Provides 24/7 support for high-severity issues
  11. Offers a robust and easy to understand documentation library 
  12. Offers role-based product training 
  13. Has registered with the Cloud Security Alliance
  14. Offers a money-back guarantee
  15. [Your additional requirement here]