Alessandro AleddaInsider Threat and Risk

INTRA/GV/GV013Periodic program review

The revision of each component of the program at a stated interval.

Pillar
GV  |  Governance and mandate
Sources cited
3
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
GV013/NOMandatoryNorwayArbeidsmiljøloven, sections 9-1 and 9-2Storting · read 29 Aug 2026That a control measure needs objective grounds in the undertaking and must not be a disproportionate burden, and that it is discussed with the elected representatives, notified with its expected duration, and evaluated with them at intervals.The need for the measures is evaluated at intervals, and the evaluation is made together with the elected representatives rather than by the employer alone.
RecommendedUnited Kingdomwhere writtenInsider Risk Mitigation FrameworkNPSA · read 11 Aug 2026A structure for an insider risk management program that an organization reviews itself against, with governance and culture as foundations rather than adjuncts.The framework is offered as something an organization reviews itself against, which makes the review a recurring act rather than a one-off inspection.
ReportedUnited Kingdomwhere writtenSystematic analysis of security advice on the topic of insider threatsStewart and Hobbs · read 11 Aug 2026What the published guidance on insider threat actually instructs a reader to do, the advice literature being the object of study.The advice literature has itself been coded and characterised, so what guidance instructs can be examined rather than assumed.