INTRA/IV/IV001Internal reporting channel
The route through which a person inside the organization reports a concern about another, and the protection owed to them for doing so.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| Recommended | Austriawhere written | Österreichisches Informationssicherheitshandbuch 4.4.0Bundeskanzleramt und A-SIT · read 29 Aug 2026 | That logging is only effective as a security measure once someone independent reads it, that where nobody independent can, the administrators’ own activity is what stops being checkable, and that the evaluation goes before the data protection officer either way. | The routes by which something conspicuous in the logs is reported onward are to be laid down, alongside the fixing of who is responsible for the evaluation that found it. |
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Staff are to be trained on how and where to report suspicious activity and on why reporting it in time matters, and the organization is to promote a culture in which an employee feels safe reporting a concern without fear of retaliation. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Reporting routes suited to each kind of incident should be built, so that an employee can report quickly and simply over channels that are reliable and can be trusted, and where a central point is set up for it that is communicated to everyone. A communication and contact strategy should state who must be informed and who may be, by whom, in what order, and in what depth, and who passes information about an incident outside. That nobody unauthorized passes it on is to be ensured. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | Everyone, internal and external, has demonstrably taken notice of the procedure for reporting an information security incident. |
| Recommended | United Kingdomwhere written | Ongoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026 | Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate. | Reporting routes are treated as a control in their own right, and their value as depending on whether they are trusted. |
