Software Engineering Institute (SEI) Podcast Series · Members of Technical Staff at the Software Engineering Institute

Getting the Most Out of Your Insider Risk Data with IIDES

·39 min·2 clips
IDES specifies seven core components, including incident information, insider information, organization information, TTPs, detection, and response.
1. Software Engineering Institute (SEI) Podcast Series episode "Getting the Most Out of Your Insider Risk Data with IIDES" focuses on the Insider Incident Data Expression Standard, or IDES. 2. Dan Costa, a technical manager on the CERT division's enterprise threat and vulnerability management team, hosts the discussion with Austin Wisnant, a senior researcher who led the standard's development. 3. The episode asks why the SEI turned an internal insider-incident schema into a public standard and what problem IDES is meant to solve. 4. Austin says the SEI has built its own repository of insider-incident information for more than a decade and now has a codified schema on GitHub. 5. Dan says the project grew from about 20 years of insider risk research and lessons learned about what data is useful to collect. 6. Austin explains that IDES includes a standard itself, documentation, and a JSON schema for implementation. 7. Dan says the SEI blog post links to the standard, the documentation, and the supporting materials for public access. 8. Austin names seven core components in IDES: incident information, insider information, organization information, TTPs, detection, response, and related subcomponents like targets and impact. 9. Austin gives North American Industry Classification System sector codes as an example of a reused vocabulary inside IDES. 10. Austin says insider-specific vocabularies are needed because cyber vocabularies often miss behaviors like using a colleague's account or a logic bomb. 11. Dan says insider response options differ from external cyber defense because organizations can retrain people, reduce stressors, or recognize work differently. 12. Austin says the standard helps analysts build timelines and track stressors when different people use different labels for the same behavior. 13. Dan says information about jobs, access levels, and titles matters for trend analysis across incidents. 14. Austin says IDES was designed with four guiding principles: simplicity, expertise, flexibility, and interoperability. 15. Austin says the team did not want to reinvent existing technical standards such as MITRE ATT&CK or other simulation standards. 16. Austin says organizations can start with a small subset of fields, use the JSON schema, or apply PyIDEs for Python-based workflows. 17. Dan says IDES can support hub-and-spoke reporting models, cross-organization sharing, and consistency across analytics, reporting, and case management. 18. Austin says the team wants feedback through GitHub pull requests, issues, discussions, or the SEI feedback address. 19. The episode is an interview format with two SEI practitioners speaking in an informal, collaborative way and using practical examples throughout. 20. Listeners who work on insider risk programs, data schemas, or threat analytics will get the most value, while casual listeners looking for general cybersecurity news may skip it.

As heard by us

A clear standards conversation that turns messy insider-risk records into usable analysis.

This episode follows a practical conversation about turning insider-risk data into something consistent enough to compare, analyze, and actually use.

Read the full review in PlayNext →

Why you'd press play

If your insider-risk data feels scattered, this gives you a cleaner way to think about what to collect, track, and standardize.

Read the full recommendation in PlayNext →
Listen to the show on