L1: run saved searches · L3: complex correlation · L5: define standards & mentor
Insider threat analysis is high-stakes, low-base-rate work. The biases that trip us up aren't exotic — they're the ones we use every day without noticing. Training on these is not optional.
Free training: Harvard — Making Sense of Data · CIA — Psychology of Intelligence Analysis (PDF) · Coursera — Critical Thinking
Hover for definitions.
Code recognition: identify Python, Bash, PowerShell, JavaScript, Java, C/C++ in logs and investigations.
Linked roles go to NICCS work role descriptions. KSAs from adjacent roles appear with purple tags in the KSA panel.
Fields flow into PDF and job description exports.