Alessandro AleddaInsider Threat and Risk

INTRA/PS/PS004Screening during employment

The repetition of verification, in whole or in part, at a stated interval and on stated events: a move into a role of greater exposure, a return after a long absence, and a concern raised through any of the routes the program keeps open.

Pillar
PS  |  Personnel security
Sources cited
5
Added
30 AUGUST 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
PS004/EUMandatoryEuropean UnionCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the assignment of people to the roles that carry security responsibilities is reviewed at planned intervals and at least once a year, and changed where the review calls for it. For a critical entity the background check is not confined to recruitment either: it may be requested on a person who already holds the sensitive role or the authorization, in duly reasoned cases and against the Member State risk assessment.
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.The background check is repeated periodically for the people in sensitive roles, so it is a standing condition of holding the role rather than a gate at the entrance.
RecommendedFinlandwhere writtenKatakri 2020Kansallinen turvallisuusviranomainen · read 29 Aug 2026The criteria an authority audits against, among them the requirement to recognize which functions call for special trustworthiness, a clearance graded on three scales, and log retention set by the limitation periods of the criminal law.The clearances, the handling rights, the rights of use, the access rights, and the awareness of the duty not to disclose are all kept updated as changes occur, and the training that goes with a change is given before the change.
RecommendedUnited Kingdomwhere writtenOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Contracting is covered alongside employment, so the standard is set for people the organization does not employ.