Alessandro AleddaInsider Threat and Risk

INTRA/IR/IR007Notification to affected persons

The telling of the people whose data or whose position the incident affected.

Pillar
IR  |  Incident response
Sources cited
1
In ITER
T1  |  Disclosure of personal data · T3  |  Alteration or destruction of records · T4  |  Interruption of an operational service · T5  |  Unauthorized consultation, without extraction
Added
30 AUGUST 2026
Updated
10 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
IR007/ITMandatoryItalyDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.Procedures are documented for telling the recipients of a service, without unjustified delay, of a significant incident that may bear adversely on the provision of that service, and for telling those exposed to a significant threat what its nature is and what they can do about it. Separate procedures cover informing the public where the agency orders it.