Alessandro AleddaInsider Threat and Risk

INTRA/ESSpain

What the record establishes for Spain, measure by measure, and what each source requires of the measure it governs.

Binding
29
Recommended
0
Reported
0
Measures touched
29 of 110
Sources cited
3
ControlSourceWhat it establishesPrerequisite or recommendation
29Mandatory
AW001/ESWorkforce awareness on insider riskMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The workforce is reminded periodically of the security rules on the proper use of the equipment and of the commonest social engineering techniques, of how to identify an incident and the activities or behaviors that are suspicious and have to be reported so that specialized staff can deal with them, and of the procedure for reporting, whether what is reported turns out to be real or a false alarm.
AW003/ESRole-specific trainingMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The workforce is trained regularly in what their duties require of them, and three subjects are named: the configuration of systems, the detection of and reaction to incidents, and the handling of information on any medium, which is to cover its storage, transfer, copying, distribution, and destruction. The effectiveness of the training given is assessed.
CP005/ESReferral to law enforcementMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Evidence that may fall to be settled before a court is recorded as such, and the prosecution of an offense is one of the three cases the decree names for it, alongside disciplinary action against internal staff and against an external supplier. What that evidence has to comprise, and in what detail, is settled on specialized legal advice.
DP004/ESAccess control and least privilegeMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The access control system is organized so that two or more people have to concur on a critical task, and the decree says what that is for: to cancel the possibility that a single authorized individual could abuse their rights to commit an unlawful or unauthorized act. All access is forbidden save on express authorization, privileges are cut to the minimum needed to do the work, and only staff with the competence to do so may grant, alter, or annul an authorization.
DP005/ESPrivileged access managementMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Development and operation are not to fall to the same person, nor are authorizing a use and controlling it. At the high category the same person may not hold configuration and maintenance together, and auditing or supervision may not be combined with any other function at all. Accounts carrying audit privileges are strictly controlled and personal to their holder, and the system’s security information is reachable only by the authorized administrators.
DP007/ESData loss prevention deploymentMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Express prior information to the workers is required before the loss prevention capability is put into operation.
DP008/ESData loss prevention policy and tuningMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.The criteria for using the capability are drawn up with the participation of the workers’ representatives, which places the rules themselves, and not only the decision to deploy, inside what is settled with them.
IR002/ESContainment of an incident in progressMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.At the high category the system carries out predetermined responses to its own alerts automatically, and the decree names them: ending the process that caused the alert, disabling particular services, disconnecting users, and blocking accounts.
IR003/ESWithdrawal of access during a caseMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.At the high category the system carries out predetermined responses to its own alerts automatically, and two of the four named reach the person: disconnecting users, and blocking accounts. The decree puts them under the detection measure, so what triggers them is an alert and not a finding.
IV010/ESDecision recordMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Every action bearing on the handling of an incident is recorded, the initial, intermediate, and final reports among them. Evidence that may have to be settled before a court is recorded as such, and the decree names when that matters most: where the incident may lead to disciplinary action against internal staff or an external supplier, or to the prosecution of an offense. Specialized legal advice is taken on what those evidences have to comprise.
MD002/ESLog collection and centralizationMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The audit record carries at least the identifier of the user or entity the event belongs to, the date and time, what information the event was performed on, the type of event, and whether it succeeded or failed. Above the low level the security documentation states which events are audited and how long the records are kept before deletion, the clock is an administration function protected by authentication and integrity, and the records and their backups may be reached or deleted only by duly authorized personnel.
MD003/ESDetection use case developmentMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.At the high category, measures are applied to prevent, detect, and react to attempts at data mining: the queries are limited, their volume and frequency are monitored, and suspicious behavior is alerted to the security administrators in real time. Systems for detecting advanced threats and anomalous behavior are required at the same category, alongside tools that analyze the activity and the audit information looking for possible or actual compromises.
MD004/ESEndpoint activity monitoringMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the endpoint agent into operation.
MD005/ESNetwork and egress monitoringMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the traffic inspection into operation.
MD006/ESElectronic mail and collaboration monitoringMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the recording of the messaging platform into operation.
MD008/ESAccess to the content of communicationsMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Content may be looked at only to check that work obligations are being met and that the device is sound, and no further.
MD011/ESPrivileged session recordingMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the session recorder into operation.
MD012/ESUser and entity behavior analyticsMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the analytics engine into operation.
MD013/ESPhysical access monitoringMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the access-control recording into operation.
MD014/ESVideo surveillance of the workplaceMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Camera images may be processed for the control functions in article 20.3, on condition of express prior information to the workers and their representatives.
MD015/ESGeolocation of vehicles and devicesMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Location data may be processed for the control functions in article 20.3, on the same condition of express prior information.
MD016/ESMeasurement of pace and performanceMandatoryLey Orgánica 3/2018, articles 87, 89, and 90Cortes Generales · read 16 Aug 2026A right to privacy in employer-provided devices, and the express prior information owed before camera images or location data are processed.Criteria for use, drawn up with the participation of the workers’ representatives, and express prior information to the workers, are required before putting the measurement into operation.
MD017/ESMonitoring on worker-owned devicesMandatoryResolución del procedimiento sancionador PS/00454/2024Agencia Española de Protección de Datos · read 16 Aug 2026What an employer may require of a device it does not own, on facts of continuous recording, at a fine of 200,000 euros.Requiring a worker’s own telephone to carry the instruments has drawn infringements of articles 13, 5(1)(c), and 6(1), a fine of 200,000 euros, and an order to bring the processing into line within two months.
MD021/ESDetection coverage assessmentMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Analyzing an incident is what reopens the question of what is audited: the determination of the auditable events is reviewed as a consequence of the analysis.
PS001/ESPre-employment screeningMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.The requirements a person has to satisfy to hold a post are defined, in particular on confidentiality, and they are taken into account in selecting who will hold it. What is verified is named: the employment history, the training, and other references, in conformity with the law and with respect for fundamental rights.
PS002/ESRisk-tiered screening standardsMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.For each post directly bound up with the handling of information or services, the security responsibilities it carries are defined, and they are based on the risk analysis. The measure does not apply at the basic category and applies at the two above it, so the scheme grades the obligation itself by what the system holds.
PS003/ESScreening of privileged-role holdersMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Security and system administrators hold a personal security clearance granted by the competent authority, either because the risk analysis called for it or because a particular system requires it.
PS005/ESContractor and third-party personnel standardsMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Where staff are contracted through a third party, the duties and obligations of each party and of the contracted staff are established, and so is the procedure for resolving an incident arising from a failure to meet them.
PS006/ESOnboarding security briefingMandatoryReal Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action.Each person working on the system is informed of the duties and responsibilities their post carries: the disciplinary measures that may follow, what is owed during the post and what is owed on its ending or on a move to another, and the duty of confidentiality over the data they reach, both while they hold the post and afterwards. Above the basic category, express confirmation that the person knows the security instructions and accepts them has to be obtained.