Committee on National Security Systems Directive 504 (CNSSD 504), issued February 4, 2014, is the federal standard requiring executive branch agencies and their cleared contractors to detect and prevent insider threats on classified national security systems. It implements Executive Order 13587 and works alongside the 26 national minimum standards for insider threat programs. The full text of the directive is marked For Official Use Only and has not been released publicly, so what is knowable about it comes from the National Insider Threat Task Force (NITTF) guidance, the executive order, and the minimum standards it implements.1Office of the Director of National Intelligence. NITTF Policy and Legal
An insider threat, as the directive uses the term, is anyone with legitimate access to classified systems or data who uses that access to cause harm, whether intentionally or through negligence. The directive grew out of Executive Order 13587, which President Obama signed in 2011 after high-profile leaks exposed serious gaps in how agencies protected classified networks.
Who Has to Comply
Every executive branch department and agency that operates or accesses classified computer networks is covered. Executive Order 13587 puts the obligation on agency heads. Each must designate a senior official to oversee classified information sharing and safeguarding, implement an insider threat detection and prevention program, and perform annual self-assessments of compliance.2The White House. Executive Order 13587 – Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information
Cleared industry falls under the same umbrella. Defense contractors and other private organizations that handle classified information within these systems must build their own insider threat programs. Under the National Industrial Security Program Operating Manual, now codified at 32 CFR Part 117, cleared contractor facilities must designate an Insider Threat Program Senior Official, self-certify their program plan to the Defense Counterintelligence and Security Agency, and produce that plan during security reviews.3Defense Counterintelligence and Security Agency. Information on Pending Insider-Threat Program Requirements for Industry A contractor that fails these requirements risks losing its facility security clearance, which ends its ability to perform classified work.
What Counts as a National Security System
Federal law defines a national security system as any information system, including telecommunications, that an agency or its contractor operates for certain sensitive purposes: intelligence activities, cryptologic work related to national security, command and control of military forces, equipment integral to weapons systems, and systems critical to military or intelligence missions. It also covers any system protected at all times under classification procedures established by executive order or statute.4Office of the Law Revision Counsel. 44 USC 3552 – Definitions
Routine administrative systems for payroll, finance, logistics, and personnel management are explicitly excluded, even when they sit inside a defense agency. The directive does not reach them.
The 26 Minimum Standards
The White House Memorandum on National Insider Threat Policy and Minimum Standards lays out 26 requirements every covered agency must meet. The NITTF’s 2024 compendium organizes them into functional groups.5Office of the Director of National Intelligence. Insider Threat Guide – A Compendium of Best Practices to Accompany the National Insider Threat Minimum Standards
Program Leadership and Policy
Each agency designates a senior official responsible for the insider threat program. That official develops internal policy, produces an implementation plan, and submits an annual status report. Agencies must coordinate program activities with their Office of General Counsel and civil liberties or privacy officials, establish records handling and retention procedures, and facilitate oversight reviews for legal compliance.6Office of the Director of National Intelligence. Insider Threat Program Activities and Compliance with Trusted Workforce 2.0
Staffing and Training
Program personnel must be trained in counterintelligence and security fundamentals, response actions, gathering and safeguarding records, applicable privacy laws, and investigative referral requirements. Cleared employees have a separate obligation: initial insider threat awareness training before gaining access to classified information, with annual refreshers afterward. Agencies also maintain an internal site with insider threat information and a secure reporting channel for employees.
Access to Information
An insider threat program cannot function in isolation. The minimum standards require that programs get timely information from counterintelligence, security, information assurance, and human resources. Agencies must set procedures for program personnel to access sensitive or protected data, create reporting guidelines so individual departments know when and how to refer information, and give the program timely access to counterintelligence reporting on adversarial threats targeting the agency.
User Activity Monitoring: The Five Technical Capabilities
The technical backbone of CNSSD 504 is User Activity Monitoring (UAM). The directive defines UAM as the technical capability to observe and record a person’s actions on any device accessing government information, at any time, for the purpose of detecting insider threats and supporting authorized investigations.7Office of the Director of National Intelligence. NITTF Tech Bulletin 20172710 – How CNSSD 504 Defines UAM
Annex B of CNSSD 504 requires five minimum technical capabilities on every classified network:
- Keystroke monitoring, recording what users type on classified systems.
- Full application content, capturing activity within email, chat, data imports, and data exports.
- Screen capture, taking periodic or triggered snapshots of what appears on a user’s display.
- File shadowing, tracking documents even after their names or storage locations change.
- User attribution, tying all collected data back to a specific individual rather than a device or account.
Without reliable attribution, anomalies flagged by the system are noise. The collected data must feed into an analysis capability that can identify anomalous behavior across the whole organization.7Office of the Director of National Intelligence. NITTF Tech Bulletin 20172710 – How CNSSD 504 Defines UAM
Agencies must monitor user activity on all classified networks, either through internal tools or through agreements with external providers. They must adopt policies governing how UAM data is protected, interpreted, stored, and accessed. Network banners on classified and unclassified systems must inform users that their activity is subject to monitoring, and every cleared employee must sign a user agreement acknowledging that.
Personnel Data and Reportable Conduct
Technical monitoring alone does not tell the full story. Agencies must integrate broader personnel data into their analysis, including human resources records, disciplinary history, and financial information that might point to vulnerability. A technical red flag, such as repeated attempts to access files outside someone’s normal duties, means more when paired with a real-world stressor like severe financial problems or unexplained foreign contacts.
Security Executive Agent Directive 3 (SEAD 3) establishes separate but overlapping reporting requirements for cleared individuals. Under SEAD 3, employees with security clearances must report foreign travel and contacts, arrests or criminal conduct, financial problems, substance abuse, security violations, unauthorized disclosures, and outside employment. These self-reports feed the same analytical picture insider threat programs use to assess risk.
Privacy, Civil Liberties, and Whistleblower Protections
Because the scope of monitoring is broad, the framework builds in explicit guardrails. Executive Order 13587 requires that implementation be consistent with applicable law and with appropriate protections for privacy and civil liberties. The order also carves out whistleblowers: insider threat programs cannot be used to deter, detect, or mitigate disclosures that are lawful under the Intelligence Community Whistleblower Protection Act, the Whistleblower Protection Act, or the Inspector General Act.2The White House. Executive Order 13587 – Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information
At the program level, the minimum standards require that insider threat personnel receive training in applicable civil liberties and privacy laws. Program activities must be coordinated with the Office of General Counsel and with civil liberties or privacy officers. Network banners and signed user agreements do double duty, giving the government legal authority to monitor and putting employees on clear notice that activity on classified systems is not private.
What Happens When a Threat Is Identified
Detection is only half the requirement. Each agency must maintain a centralized capability to analyze potential threats and coordinate response actions. Within the Department of Defense, criminal allegations must be referred to the appropriate defense criminal investigative organization as soon as possible, and any information suggesting affiliation with foreign entities or international terrorist organizations goes to the supporting counterintelligence organization.8Enterprise Services Directorate. DoD Instruction 5205.16 – The DoD Insider Threat Program
Not every case involves espionage. Some referrals produce administrative actions such as revoking access, reassigning duties, or opening a security clearance review. The program must document every matter reported and every response action taken, creating an audit trail that supports accountability and any later legal proceedings.
Oversight and NITTF Assessments
Executive Order 13587 established a Senior Information Sharing and Safeguarding Steering Committee to oversee government-wide implementation. Agencies submit annual self-assessments to that committee, reporting successes and shortcomings in sharing and safeguarding classified information.2The White House. Executive Order 13587 – Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information
The NITTF conducts independent assessments to determine whether an agency actually meets the minimum standards. Every executive branch department and agency that holds national security information or operates a classified network is subject to these reviews. An independent assessment gives the agency an outside view of its progress, identifies best practices already in place, and makes recommendations for the work that remains. Those recommendations become the roadmap for tailored NITTF assistance toward what the task force calls “full operating capability,” meaning all 26 minimum standards are implemented and functioning.9Office of the Director of National Intelligence. NITTF Assessments
How This Differs From Continuous Vetting
Trusted Workforce 2.0 is modernizing how security clearances are investigated and maintained, replacing periodic reinvestigations with continuous vetting. Because both continuous vetting and insider threat programs rely on behavioral data, agencies sometimes conflate the two. The NITTF has clarified that insider threat programs, while complementary to personnel security and continuous vetting, are independent from them. Running an insider threat program at full capability is not a mandated requirement of Trusted Workforce 2.0, and running continuous vetting does not satisfy CNSSD 504, though agencies should share relevant information between the two.6Office of the Director of National Intelligence. Insider Threat Program Activities and Compliance with Trusted Workforce 2.0
Adjudicatively relevant insider threat information can feed continuous vetting as a partial data source. But the analysis, response actions, and organizational structures stay distinct. An agency with a mature continuous vetting process still needs a separate, functioning insider threat program to comply with CNSSD 504 and the national minimum standards.