INTRA/GV/GV005Shared definitions and severity scale
A written agreement among the functions on what constitutes an event, what constitutes a condition, and what a given severity denotes.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The organization is to define what an insider threat is, clearly, and the definition offered runs on intent and on standing: malicious, negligent, or compromised, and covering employees and contractors alike. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | What counts as a security incident has to be defined clearly and marked off, as far as it can be, from the disruptions of ordinary operation. Everyone involved in handling one has to know the definition, and the definition and the thresholds at which it is met should follow the protection the affected processes, systems, and applications need. A single procedure for classifying incidents and disruptions should be settled, and agreed between security management and the function that handles ordinary faults. |
| Recommended | United Kingdomwhere written | NPSA Changes to Insider Risk DefinitionsNPSA · read 11 Aug 2026 | Revised definitions of insider, insider risk, insider threat, and insider event, organized around intent. | The definitions of insider, insider risk, insider threat, and insider event were revised, and they are organized around intent. |
| Recommended | United Kingdomwhere written | Setting the Foundations: Five Principles for a Shared Approach to Insider RiskNPSA · read 11 Aug 2026 | Five principles offered as a shared basis, with intentional and unintentional events placed on one spectrum of intent. | The definitions are agreed to be used consistently, and intentional and unintentional events are held on one spectrum so that a severity scale does not have to choose between them. |
