Alessandro AleddaInsider Threat and Risk

INTRA/CZCzechia

Nothing in the record binds here. What stands for Czechia is guidance and research written there, set against the measures it bears on.

Binding
0
Recommended
0
Reported
7
Measures touched
7 of 110
Sources cited
1
ControlSourceWhat it establishesPrerequisite or recommendation
7Reported
BA003Multidisciplinary case reviewwhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The examination is divided between three functions rather than held by one. Security analysts secure, process, and interpret the digital traces. Human resources holds the communication with the person and the impartial and dignified treatment of them, coordinates the other teams, documents the examination, and makes the final assessment against the organization’s own rules. Legal answers for its conformity with the law of the state and of the sector, evaluates what is found, and states where a public authority has to be told. The person’s line manager usually takes part, to supply the context of the activity that was observed.
CP001Disciplinary action on monitoring evidencewhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The final assessment of the examination is made against the organization’s own rules and recommendations, and it is from that assessment that disciplinary proceedings follow, where they follow.
DP002Information classification schemewhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The classification level of a document governs how a person may work on it, with whom it may be shared, and where and how it may be kept. A document carrying the right level can then be followed by the loss prevention tooling, and access to it that was not permitted is raised as an incident.
DP009Egress channel controlwhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.Restricting the channels through which a person can move data, personal mail, printing, writing to external media and to cloud storage, is treated as a proactive measure, and where it cannot be applied to the whole workforce it is applied to the users who have given or received notice.
IR006Notification to a supervisory authoritywhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.It falls to the legal function to state where an incident has to be reported to a public authority, and where personal data have been lost the supervisory authority is to be told without undue delay.
MD012User and entity behavior analyticswhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The pattern is built by watching behavior over a long period, and what is looked for against it is named: a person taking an interest in documents from projects they do not ordinarily work on, and a rise in documents pulled down from central repositories onto a workstation.
PS009Line management engagementwhere writtenReportedRedefining Threats: Extending the Threat Response Focus from External to Internal ThreatsHološka and Doucek · read 30 Aug 2026How the examination of an employee is divided between security, human resources, and legal, what a classification level governs once it has been applied, and which restrictions are placed on a person serving out notice when they cannot be placed on everyone.The person’s own line manager usually takes part in the examination, and what they supply is the context of the activity that was observed rather than a judgment on it.