Alessandro AleddaInsider Threat and Risk

INTRA/PS/PS002Risk-tiered screening standards

The written standard setting, for each level of exposure a role carries, what is checked and how far. Exposure, not seniority: a systems administrator two grades down reaches further than the director above them.

Pillar
PS  |  Personnel security
Sources cited
7
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
PS002/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, criteria are laid down setting out which roles, responsibilities, and authorities may be exercised only by a person whose background has been verified, and the verification is done before that person begins to exercise them. What it takes into account is stated: the classification of the assets, the systems to be reached, and the risks perceived, in proportion to the business requirements. The policy is reviewed at planned intervals. For a critical entity the tiering runs on the same principle from the other side: who may be checked is set by role rather than uniformly, being a sensitive role or an authorization to reach the premises, the information, or the control systems, directly or remotely. Alongside it the entity is to set out which categories of personnel exercise critical functions, and the check itself is to be proportionate and strictly limited to what is necessary.
PS002/ESMandatorySpainReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.For each post directly bound up with the handling of information or services, the security responsibilities it carries are defined, and they are based on the risk analysis. The measure does not apply at the basic category and applies at the two above it, so the scheme grades the obligation itself by what the system holds.
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.What the background check weighs is the classification of the information to be reached and the risks perceived, so the depth follows what the role will hold rather than where the role sits.
RecommendedFinlandwhere writtenKatakri 2020Kansallinen turvallisuusviranomainen · read 29 Aug 2026The criteria an authority audits against, among them the requirement to recognize which functions call for special trustworthiness, a clearance graded on three scales, and log retention set by the limitation periods of the criminal law.The authority has to recognize which of its functions call for special trustworthiness and reliability in the people employed in them. The clearance that follows can rest on a concise, a basic, or a comprehensive investigation, and which of the three is used depends on the information at stake.
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.Depth follows the area and not the person. In a high security area a further check is carried out on top of the basic check of trustworthiness, and where the work touches classified material the person goes through the statutory security clearance. This sits at the grade the compendium keeps for a raised protection need, which is itself settled by an individual risk analysis.
RecommendedNetherlandswhere writtenBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.The certificate of conduct is asked for on a weighing of the risk rather than as a matter of course, so what sets the depth is the assessment and not the grade of the post.