INTRA/BEBelgium
What the record establishes for Belgium, measure by measure, and what each source requires of the measure it governs.
| Control | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|
| 7Mandatory | |||
| AW002/BETransparency notice on what is observedMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | What each worker is told at installation is the monitoring policy, the purposes, whether personal data are kept and where and for how long, whether the monitoring is permanent, and what the employer and the supervising staff may do. |
| DP011/BERetention and disposal of business recordsMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | Whether personal data are kept, where they are kept, and for how long are among the things stated to the workforce before the monitoring begins. |
| GV007/BELawful basis registerMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | Four purposes are listed and the list is closed: unlawful or defamatory acts, the confidential economic interests of the undertaking, the security and technical functioning of its systems, and good faith observance of the rules it has set for using the technology. |
| GV010/BEWorker representative engagementMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | The works council is informed on every aspect of the monitoring before the system is installed, and failing a works council the prevention committee, then the union delegation, then the workers. |
| IV003/BEAuthorization to open a caseMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | Individualization is direct where the monitoring pursued the first three purposes. Where it pursued observance of the undertaking’s own rules, it is open only after the workers have been told an anomaly was found and warned that a further one of the same kind will be attributed. |
| MD005/BENetwork and egress monitoringMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | What is collected is aggregate and by workstation. Attributing it to a worker is a separate operation with conditions of its own. |
| MD020/BEAlert triage and case creationMandatory | Convention collective de travail n° 81 du 26 avril 2002Conseil national du Travail · read 29 Aug 2026 | Four purposes for which network communication data may be monitored, collection in the aggregate rather than by name, and individualization as a separate operation with conditions of its own. | Collecting and naming are two operations. The convention calls the second individualization and governs it separately from the monitoring that produced the data. |
| 19Recommended | |||
| AW001Workforce awareness on insider riskwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Insider threat awareness and reporting are to be included in the security training, by name, so that people can recognize and respond to internal risks. What the training covers is set out: how to recognize the behavioral signs, what an insider threat is, how and where to report suspicious activity and why reporting in time matters, and real cases or simulations used to show what an insider event costs. It reaches all staff, at onboarding and in the regular training, with an annual refresher. |
| AW003Role-specific trainingwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Training specific to the role is to be given to the staff who reach sensitive data or systems, on the responsibilities that reaching them carries, and cross-functional training is to be built where two kinds of expertise have to meet. |
| AW005Simulated exercises on live staffwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Phishing simulations are to be run regularly to reduce the risk of social engineering, and simulated phishing or social engineering tests are named again among the methods by which an awareness program is evaluated. |
| AW006Security culture measurementwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Whether the training reaches everyone it should, and whether it actually moves behavior, awareness, and attitude, is to be assessed. The methods are to be a mix, and surveys measuring the change in awareness, confidence, and behavior are named among them, alongside assessments before and after, simulated tests, and feedback from those who took part and those who taught. What is learned is documented and used on the next round. |
| BA001Risk indicator cataloguewhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Behavioral signs are named as things training should teach people to recognize, and three are given: unusual access patterns, the hoarding of data, and sudden changes in behavior. |
| GV005Shared definitions and severity scalewhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The organization is to define what an insider threat is, clearly, and the definition offered runs on intent and on standing: malicious, negligent, or compromised, and covering employees and contractors alike. |
| IR002Containment of an incident in progresswhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The response strategy is to weigh the need for a rapid recovery against what might be gained by observing the behavior for longer or investigating it more deeply, which makes the decision to contain a decision and not a reflex. |
| IV001Internal reporting channelwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Staff are to be trained on how and where to report suspicious activity and on why reporting it in time matters, and the organization is to promote a culture in which an employee feels safe reporting a concern without fear of retaliation. |
| IV002Case intake and triagewhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The criteria for categorizing, prioritizing, and escalating are documented in the response plan and applied consistently, and the indicators that guide the prioritizing are named as the scope, the severity, and how time sensitive the matter is. |
| IV005Forensic acquisitionwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The sequence of events is reconstructed and the systems, assets, and resources involved identified, with forensic analysis used on the collected data where it is needed, and the analysis is to reach the underlying systemic cause rather than stopping at what triggered the event. |
| IV006Chain of custodywhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Everyone involved in the response records what they did, in a way that prevents the record being tampered with or deleted, and the lead is answerable for documenting the whole investigation, its timelines, its decisions, and the sources of what it relied on. The incident data and their metadata, the source and the time of collection among them, are collected and protected so that they stay accurate, authentic, and traceable to where they came from. |
| MD002Log collection and centralizationwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The logging functionality of the protection and detection tools is enabled, the logs are backed up and kept for a period fixed in advance, and they are reviewed regularly for unusual or potentially harmful activity, on a documented procedure. |
| MD004Endpoint activity monitoringwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Endpoint and network protection tools that monitor the behavior of end users for dangerous activity are to be implemented and to be managed. What they are for is stated without euphemism: detecting risky or suspicious behavior by users on devices and networks, including the misuse of systems and attempts to get around the controls, whether these come from an attacker outside or from an insider. |
| MD012User and entity behavior analyticswhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Behavior analytics that learn what is normal and flag departures from it are named among the tools, and so is a class aimed at the misuse of user accounts, stolen credentials and insider threats among what it is said to be for. |
| PS001Pre-employment screeningwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | A background verification check should be carried out before a person is brought into a sensitive role, and it takes into account the applicable laws, regulations, and ethics in proportion to the business requirements. |
| PS002Risk-tiered screening standardswhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | What the background check weighs is the classification of the information to be reached and the risks perceived, so the depth follows what the role will hold rather than where the role sits. |
| PS003Screening of privileged-role holderswhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Personnel with access to the organization’s most critical information or technology are to be authenticated at the point of access, and the framework says what that means: the person proves their identity technically when they reach the asset, and is not merely validated once at onboarding. |
| PS004Screening during employmentwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The background check is repeated periodically for the people in sensitive roles, so it is a standing condition of holding the role rather than a gate at the entrance. |
| PS007Role change and internal transferwhere writtenRecommended | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | A human resources process for cybersecurity is developed and maintained, and it runs across recruitment, onboarding, employment, change of function, and offboarding rather than attaching to any one of them. |
