icon-carat-right menu search cmu-wordmark

CERT Insider Risk Management Measures of Effectiveness Certificate

Insider threats pose complex, enduring risks to organizations’ critical assets and require enterprise-wide efforts to manage associated risks to acceptable levels. For over 20 years, researchers in the CERT Division of the Software Engineering Institute (SEI) have been developing measurement instruments that allow organizations to identify their security posture against commonly exploited insider threat vulnerabilities. These measurement instruments were derived from the analysis of over 3,000 insider incidents. They measure the capabilities of formal insider threat and insider risk management programs against reference models that are derived from best practices and national policies. They characterize the institutionalization of the processes and practices that mature insider risk management programs rely on.

The CERT Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate program enables practitioners within insider threat and insider risk management programs to apply these measurement capabilities effectively within their own organizations. Earning this certificate helps practitioners acquire the knowledge, skills, and abilities they need to develop metrics that align with their organizations’ insider risk management goals.

Benefits of the CERT IRM-MoE Certificate

The courses required to earn this certificate supply practitioners from insider threat and insider risk management programs with the concepts and practices they need for measuring and managing their organizations' insider risk, including

  • Insider threat definitions, issues, and types
  • Insider threat prevention, detection, and response strategies
  • Requirements for a formal insider threat program
  • Designing and implementing effective insider risk management capabilities
  • Formulating a strategic action plan for long-term risk mitigation

After completing the certificate, participants may choose to be listed on the SEI website as an SEI Certificate Holder.

Who Should Get This Certificate?

  • Insider threat program practitioners (managers, analysts, etc.) looking for ways to measure the effectiveness of their insider threat and insider risk management capabilities
  • Security auditors looking for ways to extend or adapt their current auditing capabilities to comprehensively cover insider threats

Term and Renewal

The CERT Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate does not expire.

Summary of Fees

Participants can save by registering for all four components of the certificate at once:

  • $3,000 - U.S. government/academia
  • $3,500 - U.S. industry
  • $4,000 - International

The four components are also available separately. See each course or exam page for fee information. There is no additional fee for the certificate. Organizations considering this credential for a group of students can take advantage of eLearning group discounts or schedule private, instructor-led, onsite delivery of training. Email course-info@sei.cmu.edu or telephone +1 412-268-1817 for details.

Related Courses

Building an Insider Threat Program

This seven (7) hour online course provides a thorough understanding of the organizational models for an insider threat program, the necessary components to have an effective program, the key stakeholders who need to be involved in the process, and basic education on the implementation and guidance of the program.

This training is based upon the research of the CERT Insider Threat Center of the Software Engineering Institute. The CERT Insider Threat Center has been researching this problem since 2001 in partnership with the U.S. Department of Defense (DoD), the Department of Homeland Security, the U.S. Secret Service, other federal agencies, the intelligence community, private industry, academia, and the vendor community. This training course supports organizations implementing and managing insider threat detection and prevention programs based on various government mandates or guidance including: Presidential Executive Order 13587, the National Insider Threat Policy and Minimum Standards, and proposed changes set forth in the National Industrial Security Program Operating Manual (NISPOM).

Please note that successful completion of this course is a required component of the Insider Threat Program Manager and Insider Risk Management Measures of Effectiveness Certificate Programs. To learn more about these certificates and package pricing for the courses, please go to: SEI Certificates.

Register

Insider Risk Management Measures of Effectiveness Certificate Examination

To ensure continued excellence in identifying security posture, measuring the capabilities of formal insider threat and insider risk management programs, and characterizing processes and practices that mature insider risk management programs, the SEI objectively validates the student's understanding and eligibility to receive the CERT Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate.

The certificate examination evaluates the student's comprehension of insider threat definitions, issues, and types, as well as prevention, detection, and response strategies. In particular, the examination assesses the student's understanding of how to measure the effectiveness of a formal insider threat program, how to design and implement an insider risk management assessment methodology, and how to develop a system to capture traceable measurements back to the strategic goal of the organization to show the effectiveness of the insider risk program.

Learners can begin the online exam at any time. Once the examination is started, the learner will have 6 total hours to complete the examination.

After completing the certificate, participants may choose to be listed on the SEI website as an SEI Certificate Holder.

Register

Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate Package

Students who wish to purchase the certificate program package (two eLearning courses, instructor-led course, certificate exam) will receive a discount from the total cost. The program packages correspond with scheduled course dates, so select the program package that best meets your scheduling needs.

The Insider Risk Management Measures of Effectiveness Certificate Package consists of the following courses:

Please note that the two eLearning courses will be assigned immediately upon the purchase of a certificate package. The eLearning courses must be completed prior to the delivery date of the instructor-led course delivery that you chose to attend.

Register

Insider Risk Management: Measures of Effectiveness

This three-day, instructor-led course develops the skills and competencies needed to assess an organization's insider threat prevention, detection, and response capabilities; evaluate the effectiveness of formal insider threat and insider risk management programs; identify the maturity of an organization's insider risk management processes and practices; and develop tailored metrics for various aspects of insider threat and insider risk management program operation.

This training is based on the work of CERT Division researchers at the Software Engineering Institute (SEI). SEI researchers have been studying insider threats since 2001 in partnership with the U.S. Department of Defense (DoD), the Department of Homeland Security (DHS), the U.S. Secret Service (USSS), other federal agencies, the intelligence community, private industry, academia, and the vendor community.

Course participants will learn how to apply the SEI's Insider Threat Vulnerability Assessment (ITVA), Insider Threat Program Evaluation (ITPE), Insider Risk Management Program Evaluation (IRMPE), and Goal, Question, Indicator, Metric (GQIM) methodologies to achieve their insider threat and insider risk management measurement objectives. This suite of methodologies provides reference models derived from over 20 years of research, experience building insider threat programs across both public and private sectors, and detailed knowledge of the strategies that can be used to develop customized metrics for numerous applications within insider risk management.

Successful completion of this course is a requirement for earning the Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate. (To learn more about the certificate and package pricing for its required courses, please visit this page: Insider Risk Management Measures of Effectiveness (IRM-MoE) Certificate.)

NOTE: If you have previously completed the prerequisite eLearning courses and wish to earn the IRM-MoE professional certificate, you must register for the IRM-MoE Examination. Online registration for the exam is available at Insider Risk Management Measures of Effectiveness Certificate Examination

Register

Training courses provided by the SEI are not academic courses for academic credit toward a degree. Any certificates provided are evidence of the completion of the courses and are not official academic credentials. For more information about SEI training courses, see Registration Terms and Conditions and Confidentiality of Course Records.