Alessandro AleddaInsider Threat and Risk

INTRA/GV/GV004Roles and decision rights

The statement of which decisions the program may take, of the role entitled to take each, and of the person holding that role. The decisions are the ones the framework names elsewhere: to open a case on a person, to reach for the content of what they wrote, to withdraw their access before any finding, and to recommend a consequence.

Pillar
GV  |  Governance and mandate
Sources cited
3
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
GV004/ITMandatoryItalyProvvedimento del 17 aprile 2026, Framos ItaliaGarante per la protezione dei dati personali · read 29 Aug 2026That a company mailbox left running after the employment ends is a processing needing a ground of its own, and that a smooth handover and the chance of wanting something later are not one.The technician who reached into the accounts held the role and not the instruction. A signed confidentiality undertaking is not the documented instruction the Regulation asks of anyone processing on the controller’s behalf.
RecommendedUnited Kingdomwhere writtenInsider Risk Practitioners and StakeholdersNPSA · read 29 Aug 2026Board Engagement and GovernanceNPSA · read 29 Aug 2026That a program needs a senior stakeholder group drawn from named functions, and a director who carries the board’s strategy into policy.One board member holds overall responsibility for protective security, and a non-executive director acts as an independent champion for it. Below them a director carries the strategy into policy, and senior staff in each business area answer for the risk assessment and for implementation in their own.