Alessandro AleddaInsider Threat and Risk

INTRA/DP/DP006Access recertification

The periodic comparison of the access a person holds against the work they perform, and its adjustment.

Pillar
DP  |  Data and asset protection
Sources cited
4
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
DP006/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, access rights are reviewed at planned intervals and changed on organizational change, and the result of the review is documented together with the changes it called for.
DP006/ITMandatoryItalyDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, accounts and the authorizations on them are verified periodically on the systems that matter, and updated or revoked where a change calls for it.
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.Which identifiers, groups, and rights profiles have been permitted and created is documented, and the documentation is checked at intervals against the state the entitlements are actually in, and against whether what has been granted still answers to the security requirements and to what the users now do. The documentation itself is protected from unauthorized access.
RecommendedNetherlandswhere writtenBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Every access right that has been issued is assessed at least once a year.