Ensure that managers, system administrators, and users are aware of security risks.
Three requirements about people rather than machines: everyone knows the risks, the people with security duties are trained for them, and staff can recognise an insider threat. Small family, but two of the three are five-point requirements, and an assessor will ask to see the records.