INTRA/PS/PS006Onboarding security briefing
What a person is told at the point of joining: what is observed about them and why, what is expected of them, what they are to report and to whom, and what follows from a breach. Recorded as having been given, since it is relied on afterwards.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| PS006/PLMandatory | Poland | Kodeks pracy, article 22(2)Sejm of the Republic of Poland · read 20 Sep 2026Kodeks pracy, article 22(3)Sejm of the Republic of Poland · read 20 Sep 2026 | That image recording at work is open for four purposes only, one of them keeping secret information whose disclosure could harm the employer, that its purposes, scope and manner are fixed in the collective agreement, the work regulations or an announcement, that it is notified two weeks before it starts and handed to each worker before they are admitted to work, and that recordings are kept three months. | Before admitting a worker to work, the employer hands them, on paper or electronically, the purposes, the scope and the manner in which monitoring is applied. The obligation attaches to the start of the individual relationship and stands separately from the notice owed to the workforce when monitoring is introduced. |
| PS006/ESMandatory | Spain | Real Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026 | The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action. | Each person working on the system is informed of the duties and responsibilities their post carries: the disciplinary measures that may follow, what is owed during the post and what is owed on its ending or on a move to another, and the duty of confidentiality over the data they reach, both while they hold the post and afterwards. Above the basic category, express confirmation that the person knows the security instructions and accepts them has to be obtained. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | At the start of the employment the person is informed of the rules, the instructions, and the procedures that exist, and a checklist and a named contact should be set up to carry it. Every employee is obliged to keep to the law and to the internal rules, has to know the legal frame of their own work, and has their tasks and responsibilities documented. They are told that what they receive at work is for internal use only, and made aware that they protect the organization’s information security outside working hours and away from its premises as well. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | Everyone, internal and external, is pointed to their responsibilities for information security on appointment or on a change of function, and the rules and instructions that apply to them are to be simple to reach. |
