INTRA/BA/BA001Risk indicator catalogue
The defined set of observable circumstances the program treats as bearing on the likelihood of harm.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Behavioral signs are named as things training should teach people to recognize, and three are given: unusual access patterns, the hoarding of data, and sudden changes in behavior. |
| Recommended | United Kingdomwhere written | Insider Data Collection Study: Report of Main FindingsNPSA, published as CPNI · read 11 Aug 2026 | How real insider acts occurred and what preceded them, from a review of United Kingdom cases. | Real cases have been reviewed and what preceded the acts described, which is where an indicator can be taken from rather than supposed. |
| Reported | Denmarkwhere written | SoK: The Psychology of Insider ThreatsSaddiqa and Ruohonen · read 11 Aug 2026 | What has been published on traits, states, and situational factors, and that the foundations are thin and hard to compare across studies. | An indicator taken from this literature carries thin foundations with it, and findings that cannot readily be compared between studies. |
| Reported | United Kingdomwhere written | Understanding Insider Threat: A Framework for Characterising AttacksNurse, Buckley, Legg, Goldsmith, Creese, Wright, and Whitty · read 11 Aug 2026 | A vocabulary for describing an insider attack in four parts: catalyst, actor, attack, and organization. | A published vocabulary is available to build the catalogue on: catalyst, actor, attack, and organization, grounded in case studies rather than telemetry. |
