Alessandro AleddaInsider Threat and Risk

INTRA/DP/DP009Egress channel control

The restriction of the routes by which data can leave: removable media, personal cloud storage, webmail, printing, and unmanaged devices.

Pillar
DP  |  Data and asset protection
Sources cited
2
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
DP009/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, removable media carry a policy of their own, communicated to employees and to the third parties who connect them, and it provides for a technical prohibition of connections the entity has not allowed.
ReportedCzechiawhere writtenRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.Restricting the channels through which a person can move data, personal mail, printing, writing to external media and to cloud storage, is treated as a proactive measure, and where it cannot be applied to the whole workforce it is applied to the users who have given or received notice.