home/glossary/high-risk individual

high-risk individual

nounid 163516·updated Aug 30, 2026
verified

A classification applied to a person — typically a user, employee, contractor, or other organizational insider — for whom credible evidence indicates a significant likelihood of causing harm to organizational systems, data, assets, or operations, either through malicious intent or as a vector adversaries can exploit. The category is operationalized in access-control and incident-response policy: once someone is designated high-risk, controls such as time-bounded account disablement, heightened monitoring, and expedited notification of relevant personnel are triggered. Across the field the designation is context-driven and organization-defined, covering a spectrum from the disgruntled insider with demonstrated intent to the compromised account holder through whom external threat actors act.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0164
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
for high-risk individuals. Time periods for the notification of organizational personnel or roles may vary.the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A descriptive classification applied to personnel, users, or subjects whose combination of access privileges, role responsibilities, or personal circumstances creates an elevated probability or magnitude of harm—either to the organization (e.g., through insider threat, privileged misuse) or to themselves (e.g., through targeting by adversaries). In personnel-security frameworks aligned to NIST SP 800-53, the designation covers those with access to highly sensitive information assets or critical facilities, and it governs the level of screening, clearance, and training applied to those positions. Across the field the label is used contextually—not as a fixed defined term—to trigger differential controls such as enhanced background checks, accelerated or targeted security-awareness training, and priority or expedited incident notification, as in the source document's reference to varied notification time periods for high-risk individuals versus the general workforce.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.h ¶ 3

Classifications

Entity Type

Identity92%llm-generatedllm:claude-haiku-4-5

Sensitivity

Restricted85%llm-generatedllm:claude-haiku-4-5

Information Class

Pii78%llm-generatedllm:claude-haiku-4-5

Variants

plural
high-risk individuals
possessive
high-risk individual's
pluralpossessive
high-risk individuals'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A classification applied to a person — typically a user, employee, contractor, or other organizational insider — for whom credible evidence indicates a significant likelihood of causing harm to organizational systems, data, assets, or operations, either through malicious intent or as a vector adversaries can exploit. The category is operationalized in access-control and incident-response policy: once someone is designated high-risk, controls such as time-bounded account disablement, heightened monitoring, and expedited notification of relevant personnel are triggered. Across the field the designation is context-driven and organization-defined, covering a spectrum from the disgruntled insider with demonstrated intent to the compromised account holder through whom external threat actors act.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.