Alessandro AleddaInsider Threat and Risk

INTRA/GV/GV005Shared definitions and severity scale

A written agreement among the functions on what constitutes an event, what constitutes a condition, and what a given severity denotes.

Pillar
GV  |  Governance and mandate
Sources cited
4
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.The organization is to define what an insider threat is, clearly, and the definition offered runs on intent and on standing: malicious, negligent, or compromised, and covering employees and contractors alike.
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.What counts as a security incident has to be defined clearly and marked off, as far as it can be, from the disruptions of ordinary operation. Everyone involved in handling one has to know the definition, and the definition and the thresholds at which it is met should follow the protection the affected processes, systems, and applications need. A single procedure for classifying incidents and disruptions should be settled, and agreed between security management and the function that handles ordinary faults.
RecommendedUnited Kingdomwhere writtenNPSA Changes to Insider Risk DefinitionsNPSA · read 11 Aug 2026Revised definitions of insider, insider risk, insider threat, and insider event, organized around intent.The definitions of insider, insider risk, insider threat, and insider event were revised, and they are organized around intent.
RecommendedUnited Kingdomwhere writtenSetting the Foundations: Five Principles for a Shared Approach to Insider RiskNPSA · read 11 Aug 2026Five principles offered as a shared basis, with intentional and unintentional events placed on one spectrum of intent.The definitions are agreed to be used consistently, and intentional and unintentional events are held on one spectrum so that a severity scale does not have to choose between them.