Alessandro AleddaInsider Threat and Risk

INTRA/AW/AW003Role-specific training

The additional instruction given to managers, privileged users, and the people who run the program.

Pillar
AW  |  Awareness and training
Sources cited
6
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
AW003/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the employees whose roles need security-relevant skills are identified and trained regularly, and the training program sets the needs of particular roles and positions against criteria. What the training covers is named: secure configuration and operation of the systems, mobile devices included, a briefing on known threats, and how to behave when a security-relevant event occurs. It is given again to staff who move into such a role, and its effectiveness is assessed.
AW003/ITMandatoryItalyDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For an essential subject, training dedicated to the people in specialized roles, system administrators named among them, is part of the same plan, and it covers the secure configuration and operation of the systems, the threats that are known, and what to do when an event bearing on security occurs.
AW003/ESMandatorySpainReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The workforce is trained regularly in what their duties require of them, and three subjects are named: the configuration of systems, the detection of and reaction to incidents, and the handling of information on any medium, which is to cover its storage, transfer, copying, distribution, and destruction. The effectiveness of the training given is assessed.
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.Training specific to the role is to be given to the staff who reach sensitive data or systems, on the responsibilities that reaching them carries, and cross-functional training is to be built where two kinds of expertise have to meet.
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.Where the protection need is raised, particular people should be given the task of watching the logging data, it should be the greater part of what they do, and they should be given specialized further training and qualification. A group should be named that is responsible for the evaluation of logging data and for nothing else.
RecommendedUnited Kingdomwhere writtenEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.The people who handle what monitoring produces should be trained to handle it, and they are to be identified as the appropriate people for that rather than reached by default.