INTRA/MD/MD001Threat modelling and detection scoping
The derivation of what the program will look for from the harm it is trying to prevent, before any tool is chosen.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| MD001/GBMandatory | United Kingdom | Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026 | The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system. | What may be looked for is a closed list. Interception on the employer’s own system is authorized to establish the existence of facts, to ascertain compliance with regulatory or self-regulatory practices, to ascertain or demonstrate the standards achieved by the people using the system, in the interests of national security, to prevent or detect crime, to investigate or detect the unauthorized use of that or any other telecommunication system, or to secure the effective operation of the system. A purpose outside the list is not authorized by these regulations. |
| Recommended | European Unionwhere written | ENISA Threat Landscape 2020: Insider ThreatENISA · read 11 Aug 2026 | Attack vectors, incident findings, and mitigation at the level of general control categories, in the agency’s only thematic report on the subject. | Scoping starts at the level of control categories rather than of tools, and the only Union report to work from stops there and dates from 2020. |
