Alessandro AleddaInsider Threat and Risk

INTRA/GV/GV006Escalation triggers and owners

The agreement, settled between the functions before any case exists, on which conditions pass out of the team that observed them, to whom they pass, and within what time. As distinct from moving a live matter upward during a response, which the incident pillar holds.

Pillar
GV  |  Governance and mandate
Sources cited
2
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.An escalation strategy is formulated beyond the communication and contact strategy and agreed between the people who handle ordinary faults and information security management. It should say unambiguously who is to be brought in, by what route, and when, for each kind of detected or suspected disturbance, what measures an escalation leads to, and how the response is to run. The contact strategy under it settles who must be informed and who may be, by whom, in what order, and in what depth, and who may pass information about an incident outside. It is reviewed at intervals and the paths are practiced in exercises.
RecommendedNetherlandswhere writtenBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.The monitoring process in the security operations function has unambiguous rules about when an incident is reported to the management answerable for it.