Alessandro AleddaInsider Threat and Risk

INTRA/MD/MD003Detection use case development

The construction of a specific, testable rule or query that raises an alert on a defined pattern of activity.

Pillar
MD  |  Monitoring and detection
Sources cited
9
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
MD003/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, alarm thresholds are set where appropriate, an alarm is raised automatically once one is exceeded, and a qualified response follows in good time. Monitoring is to be automated as far as it can be and built so as to minimize both false positives and false negatives, and a process for correlating and analyzing logs is put in place.
MD003/ITMandatoryItalyDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, qualitative and quantitative parameters for detecting unauthorized access, or access abusing the privileges granted, are defined, monitored, and documented. The requirement is on essential subjects, and the same annexes do not place it on important ones.
MD003/ESMandatorySpainReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.At the high category, measures are applied to prevent, detect, and react to attempts at data mining: the queries are limited, their volume and frequency are monitored, and suspicious behavior is alerted to the security administrators in real time. Systems for detecting advanced threats and anomalous behavior are required at the same category, alongside tools that analyze the activity and the audit information looking for possible or actual compromises.
MD003/GBMandatoryUnited KingdomInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.Investigating or detecting the unauthorized use of that or any other telecommunication system is named in the list of purposes in its own right, so the misuse of the employer’s own system is a purpose the regulations authorize interception for rather than one that has to be brought under another.
RecommendedAustriawhere writtenÖsterreichisches Informationssicherheitshandbuch 4.4.0Bundeskanzleramt und A-SIT · read 29 Aug 2026That logging is only effective as a security measure once someone independent reads it, that where nobody independent can, the administrators’ own activity is what stops being checkable, and that the evaluation goes before the data protection officer either way.The handbook sets out what an evaluation looks for: logon and logoff times outside working hours, a build-up of failed logon attempts, a build-up of impermissible access attempts, conspicuously long intervals in which nothing was logged, which points to records having been deleted, and conspicuously long intervals in which no user appears to have changed. Particular attention is to go to every access carried out under an administrator identifier.
RecommendedNetherlandswhere writtenBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Use cases for the misuse of authentication data are defined, monitored, and acted on, and two of them are named in the text: logins from unusual places, and spikes in failed login attempts. Separately, the creation and modification of accounts carrying special rights is monitored, and where such a change was not authorized it is an information security incident and is recorded and handled as one.
RecommendedNorwaywhere writtenNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.Tools are taken into use that allow manual and automatic searching and alerting on criteria across everything collected, and that assemble data from different sources on their own so that it can be decided whether the event is real rather than a false positive, and what its extent and character are. Knowledge of the normal state and of the threats is what the searches and the alerting criteria are improved from.
ReportedUnited Kingdomwhere writtenCorporate Insider Threat Detection (CITD)University of Oxford · read 11 Aug 2026A research program combining security engineering with psychology and criminology, producing a characterization framework and a working tool.A characterization framework and a working tool came out of the research program, which is a starting point a use case can be derived from rather than invented.
ReportedUnited Kingdomwhere writtenInsider-threat detection: Lessons from deploying the CITD tool in three multinational organisationsErola, Agrafiotis, Goldsmith, and Creese · read 11 Aug 2026The operational constraints that emerged when a research detection tool ran inside three organizations for more than a year.Deploying a research tool inside three organizations for a year surfaced the operational constraints that the detection literature leaves out.