Alessandro AleddaInsider Threat and Risk

INTRA/EUEuropean Union

What the record establishes for the European Union, measure by measure, and what each source requires of the measure it governs.

Binding
52
Recommended
8
Reported
0
Measures touched
56 of 110
Sources cited
12
ControlSourceWhat it establishesPrerequisite or recommendation
52Mandatory
AW001/EUWorkforce awareness on insider riskMandatoryDirective (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds.Basic cyber hygiene practices and cybersecurity training are named among the measures an entity in scope has to take, and the implementing rules say what the awareness program holds: it is scheduled over time so that it repeats and reaches new employees, it covers the threats, the measures in place, and where to go for advice, it reaches direct suppliers and service providers as well as employees and the members of the management bodies, and it is tested for effectiveness where appropriate. What is asked to be taught is the security of systems, not insider risk.
AW003/EURole-specific trainingMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the employees whose roles need security-relevant skills are identified and trained regularly, and the training program sets the needs of particular roles and positions against criteria. What the training covers is named: secure configuration and operation of the systems, mobile devices included, a briefing on known threats, and how to behave when a security-relevant event occurs. It is given again to staff who move into such a role, and its effectiveness is assessed.
BA004/EUUse of psychological and dispositional indicatorsMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.Article 9 reaches an indicator only where it reveals one of the categories it closes off, data concerning health among them, and where it does the processing is prohibited unless one of that article’s own grounds applies. An assessment of disposition that reveals none of them is not caught by it, and falls back on the ordinary grounds.
BA006/EUInference of emotional stateMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.Putting on the market, putting into service, or using an AI system to infer the emotions of a person in the workplace is prohibited, unless the system is intended for medical or safety reasons. What the Act means by inferring an emotion it defines by reference to biometric data, and the reasoning it gives for the prohibition runs on that basis. Physical states such as pain or fatigue fall outside it, and so does the mere detection of readily apparent expressions, gestures, or movements, unless those are used to infer an emotion.
BA007/EUAutomated decision-making about a workerMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026Regulation (EU) 2026/1744, amending the Artificial Intelligence ActEuropean Parliament and Council · read 16 Aug 2026Regulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.A person has the right not to be subject to a decision taken solely by automated processing, profiling included, that produces legal effects concerning them or affects them similarly significantly. It is open only on contractual necessity, on a Union or member state law that lays down safeguards, or on explicit consent, and on the first and the third of those the person is owed at least human intervention, the chance to put their point of view, and the right to contest the outcome. Such a decision may not rest on the article 9 categories at all save on two narrow grounds. Separately, a decision of this kind falls in the high-risk category, and the obligations that follow apply from 2 December 2027.
BA008/EUDeployment of an algorithmic system in employmentMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026Regulation (EU) 2026/1744, amending the Artificial Intelligence ActEuropean Parliament and Council · read 16 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.What puts a system in the high-risk category is the purpose it is intended for and not the place it runs in: making decisions on the terms of a work relationship, allocating tasks on individual behavior or personal traits, or monitoring and evaluating the performance and behavior of the people in it. The representatives and the workers concerned have to be told before it is put into use.
BA009/EUModel validation and bias testingMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.The training, validation, and testing sets behind a high-risk system fall under data governance practices, and what those have to cover is listed: the design choices, where the data came from and, for personal data, what they were originally collected for, the assumptions about what the data are supposed to measure, an examination for biases likely to bear on health and safety, to affect fundamental rights adversely, or to lead to prohibited discrimination, especially where the outputs feed the inputs of later operations, and measures to detect, prevent, and mitigate what the examination finds. The sets are to be relevant, sufficiently representative, and so far as possible free of errors and complete, with statistical properties appropriate to the people the system is to be used on.
CP001/EUDisciplinary action on monitoring evidenceMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, a disciplinary process for handling violations of the security policies is established, communicated, and maintained, and it takes the legal, statutory, contractual, and business requirements into account. It is reviewed at planned intervals and when a change in the law calls for it. What may be relied on to establish a violation is not addressed.
CP004/EUReliance on material obtained in breachMandatoryNTH Haustechnik GmbH v EMCourt of Justice of the European Union, Fifth Chamber · read 16 Aug 2026That a court may rely on data obtained in breach, subject to minimization of what it admits and to considering anonymization before disclosure.Material obtained in breach is not barred from proceedings by that alone, and a failure to inform the person does not bar it either.
DP001/EUIdentification of critical assetsMandatoryDirective (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds.Asset management is named among the measures an entity in scope has to take, alongside access control policies and human resources security in the same point. What the identification covers, and how far it goes, is left to the state of the art.
DP002/EUInformation classification schemeMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, a system of classification levels is laid down and every asset is placed in one, on confidentiality, integrity, and authenticity. The handling policy that follows runs from acquisition through use, storage, and transport to disposal, and reaches everyone who handles an asset.
DP003/EUData discovery and inventoryMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the inventory is to be complete, accurate, up to date, and consistent, and changes to its entries are recorded so that they can be traced.
DP004/EUAccess control and least privilegeMandatoryDirective (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds.Access control policies are named among the measures an entity in scope has to take, and for one class of entity the implementing rules say what they hold: rights assigned and revoked on need to know, least privilege, and separation of duties, modified on termination or change of employment, authorized by the relevant persons, limited in scope and duration for suppliers and visitors, held in a register, and logged.
DP005/EUPrivileged access managementMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, privileged and system administration accounts carry policies of their own, strong identification and authentication among them, and the systems used to administer are kept for administration and separated from everything else.
DP006/EUAccess recertificationMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, access rights are reviewed at planned intervals and changed on organizational change, and the result of the review is documented together with the changes it called for.
DP007/EUData loss prevention deploymentMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the loss prevention capability, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
DP009/EUEgress channel controlMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, removable media carry a policy of their own, communicated to employees and to the third parties who connect them, and it provides for a technical prohibition of connections the entity has not allowed.
DP010/EUEncryption and rights managementMandatoryDirective (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds.Policies and procedures on the use of cryptography and, where appropriate, on encryption are named among the measures an entity in scope has to take.
DP016/EUPhysical access controlMandatoryDirective (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026The conditions on which a critical entity may ask for a background check, on whom, and what the check has to cover at a minimum. Also the duty to set out which categories of personnel exercise critical functions and to establish their access rights to premises.Employee security management is to set out the categories of personnel who exercise critical functions and to establish their access rights to premises, to critical infrastructure, and to sensitive information. The physical protection asked for alongside it names fencing, barriers, perimeter monitoring, detection equipment, and access controls.
GV007/EULawful basis registerMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be recorded for each stream the program collects, before it collects it, and the register has to survive the article 5(2) test of being shown rather than asserted.
GV008/EUImpact assessment before deploymentMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.The assessment has to be completed before the measure operates, not compiled after it, wherever the processing is likely to result in a high risk.
GV009/EUAccountability evidenceMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.The controller has to be responsible for the principles and able to demonstrate compliance with them, which is a duty to show rather than to assert. The article stops there. It does not itemise what has to be kept, nor does it say that every decision has to be reconstructable.
GV011/EUNotice before an algorithmic system is deployedMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026Regulation (EU) 2026/1744, amending the Artificial Intelligence ActEuropean Parliament and Council · read 16 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.Before a high-risk system is put into service or used at the workplace, the employer deploying it has to inform the workers’ representatives and the affected workers that they will be subject to it. The duty applies from 2 December 2027 for the Annex III categories.
GV014/EUAnswering a request from the personMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.The reply is owed without undue delay and in any event within one month of the request, so the month is the outer limit and not the term. It can be extended by two more where the request is complex or the requests are many, but the extension and the reasons for it have to reach the person inside the first month. Where the program will not act at all, that is said inside the same month, with the routes to a complaint and to a court named.
IR001/EUInsider incident playbooksMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, response follows documented procedures and is given in good time, and the stages those procedures have to include are named: containment, so that the consequences do not spread, eradication, so that the incident does not continue or return, and recovery where it is needed.
IR002/EUContainment of an incident in progressMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, containment is the first of the named stages of the response, and what it is for is stated: to prevent the consequences of the incident from spreading.
IR004/EUPreservation of systems and recordsMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the activities of the response are logged under the same procedures that govern the logging of everything else, and evidence is recorded. In what state a system is to be held, and for how long, is not stated.
IR006/EUNotification to a supervisory authorityMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, communication plans and procedures are established with the incident response teams or, where applicable, the competent authorities, for the notification of an incident.
IR009/EUPost-incident reviewMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, a review after the fact is carried out once recovery is done, where appropriate. It identifies the root cause where that can be done and produces documented lessons, and what those lessons are to improve is named: the approach to security, the treatment of risk, and the procedures for handling, detecting, and responding. Whether incidents led to a review at all is itself checked at planned intervals.
IR010/EUExercising the responseMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the incident response procedures are tested at planned intervals.
IV005/EUForensic acquisitionMandatoryNTH Haustechnik GmbH v EMCourt of Justice of the European Union, Fifth Chamber · read 16 Aug 2026That a court may rely on data obtained in breach, subject to minimization of what it admits and to considering anonymization before disclosure.What a court admits has to be confined to the adequate, relevant, and necessary, and anonymization or pseudonymization considered before it goes to other parties.
MD002/EULog collection and centralizationMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the list of assets to be logged is derived from the risk assessment, and what the logs hold is named: inbound and outbound traffic, the creation, modification, and deletion of users and the extension of their permissions, access to systems and applications, authentication events, all privileged access and everything done by administrative accounts, access or changes to critical configuration and backup files, physical access to facilities, and the activation, stopping, and pausing of the logs themselves. They are kept for a period fixed in advance and protected from unauthorized access or change, time sources are synchronized so that logs can be correlated across systems, and the availability of the logging systems is monitored independently of the systems they log.
MD003/EUDetection use case developmentMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, alarm thresholds are set where appropriate, an alarm is raised automatically once one is exceeded, and a qualified response follows in good time. Monitoring is to be automated as far as it can be and built so as to minimize both false positives and false negatives, and a process for correlating and analyzing logs is put in place.
MD004/EUEndpoint activity monitoringMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the endpoint agent, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD005/EUNetwork and egress monitoringMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the traffic inspection, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD006/EUElectronic mail and collaboration monitoringMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the recording of the messaging platform, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD011/EUPrivileged session recordingMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the session recorder, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD012/EUUser and entity behavior analyticsMandatoryRegulation (EU) 2024/1689, articles 5(1)(f), 10, and 26(7), and Annex III(4)European Parliament and Council · read 11 Aug 2026Regulation (EU) 2026/1744, amending the Artificial Intelligence ActEuropean Parliament and Council · read 16 Aug 2026That inferring emotions at work is prohibited, that employment and worker management are a high-risk category, what the data a high-risk system is trained and tested on have to answer for, and that representatives are told before deployment.Whether the engine falls in the high-risk category turns on whether it is intended to monitor and evaluate the performance and behavior of the people it watches. Where it does, the full set of obligations follows, and none of that settles whether the detection method is lawful under data protection or employment law.
MD013/EUPhysical access monitoringMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the access-control recording, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD014/EUVideo surveillance of the workplaceMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the cameras, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD015/EUGeolocation of vehicles and devicesMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the tracking device, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD016/EUMeasurement of pace and performanceMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026Opinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.A ground under article 6 has to be identified before anything is collected through the measurement, and whatever more specific rule the member state has made under article 88 applies on top of it. Consent is rarely that ground in an employment relationship, since it has to be freely given and the imbalance there makes that doubtful.
MD020/EUAlert triage and case creationMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, a suspicious event is assessed against criteria laid down in advance and against a triage that decides what is dealt with first. The relevant logs are reviewed for that assessment, and an event is reassessed and reclassified when new information arrives or when what was already held has been analyzed.
MD021/EUDetection coverage assessmentMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, two lists are required: the assets that are to be logged, derived from the risk assessment, and the assets that are actually being logged. The second, and the procedures behind it, are reviewed and where appropriate updated at regular intervals and after a significant incident. That the two are to be held against each other is not stated.
PS001/EUPre-employment screeningMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, verification of an employee’s background is required as far as it can be done, where it is necessary for the role, the responsibilities, and the authorizations held. The mechanisms for hiring are named in the same place: reference checks, vetting procedures, validation of certifications, or written tests. For a critical entity the persons a check may be requested on include those under consideration for a sensitive role, or for a role authorized to reach the premises, the information, or the control systems. That check corroborates identity and examines the criminal record for offences relevant to the specific position, and it is carried out for the sole purpose of evaluating a security risk.
PS002/EURisk-tiered screening standardsMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, criteria are laid down setting out which roles, responsibilities, and authorities may be exercised only by a person whose background has been verified, and the verification is done before that person begins to exercise them. What it takes into account is stated: the classification of the assets, the systems to be reached, and the risks perceived, in proportion to the business requirements. The policy is reviewed at planned intervals. For a critical entity the tiering runs on the same principle from the other side: who may be checked is set by role rather than uniformly, being a sensitive role or an authorization to reach the premises, the information, or the control systems, directly or remotely. Alongside it the entity is to set out which categories of personnel exercise critical functions, and the check itself is to be proportionate and strictly limited to what is necessary.
PS003/EUScreening of privileged-role holdersMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, among the things the verification takes into account are the network and information systems the person is to reach, so what the access reaches is part of what sets the depth of the check. Separately, the people holding administrative or privileged access are to be made aware of their roles, responsibilities, and authorities, and to act in accordance with them. For a critical entity, holding a sensitive role in or for it, or being authorized to reach its premises, information, or control systems, is what brings a person within the checks, and the reach may be direct or remote.
PS004/EUScreening during employmentMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026Directive (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, the assignment of people to the roles that carry security responsibilities is reviewed at planned intervals and at least once a year, and changed where the review calls for it. For a critical entity the background check is not confined to recruitment either: it may be requested on a person who already holds the sensitive role or the authorization, in duly reasoned cases and against the Member State risk assessment.
PS007/EURole change and internal transferMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, access rights are modified on a change of employment and not only on its end, so a move inside the organization is an event the entitlements have to answer to.
PS008/EULeaver processMandatoryCommission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings.For the digital infrastructure and service providers it reaches, access rights are modified on termination, and the register of what was granted is what the withdrawal is checked against.
PS011/EURecords concerning trade union activityMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.Trade union membership is one of the categories article 9 prohibits the processing of outright. The prohibition lifts only on one of that article’s own grounds, and the employment one requires that Union or member state law or a collective agreement authorize the processing and provide appropriate safeguards for the person.
PS012/EURecords concerning health held for security purposesMandatoryRegulation (EU) 2016/679, articles 5(2), 6, 9, 12, 15, 22, 35, and 88European Parliament and Council · read 11 Aug 2026The grounds on which processing may rest, the burden of showing it, the categories whose processing is prohibited outright save on a named ground, what a person asking has to be told and by when, the limit on deciding about someone by machine alone, when an impact assessment is owed, and the leave each member state has to set its own employment rule.Data concerning health are one of the categories article 9 prohibits the processing of outright, so a security purpose is not on its own what makes holding them lawful. The prohibition lifts only on one of that article’s grounds, and the employment one requires that Union or member state law or a collective agreement authorize it and provide appropriate safeguards.
8Recommended
AW001Workforce awareness on insider riskwhere writtenRecommendedHelp2ProtectCoESS and partners, co-funded by the Internal Security Fund of the European Union · read 11 Aug 2026Awareness and program-building material for critical infrastructure operators, with templates, and no legal basis stated for any of it.A Union-funded platform carries an awareness module and downloadable templates, addressed mainly to transport, energy, and other critical infrastructure operators.
AW001Workforce awareness on insider riskwhere writtenRecommendedInsider Threat Program Development ManualCoESS, co-financed by the Internal Security Fund of the European Union · read 11 Aug 2026The structure of an insider risk management program, as the closest thing to doctrine issued under European Union funding, unrevised since 2019.The Union-funded manual addresses the structure of a program rather than the conditions attached to one, and has not been revised since 2019.
DP016Physical access controlwhere writtenRecommendedSecure personal dataEuropean Data Protection Board · read 1 Sep 2026What controlling access to a building is taken to consist of, area by area, and what the Board says is owed before access to those areas is recorded.The building is divided into areas according to risk, and for each area a list is kept of the individuals, or the categories of individual, permitted to enter it. Rules and means are established for visitors, at a minimum that a visitor is accompanied by someone from the organization once outside the public areas. The keys and the alarm codes are themselves protected.
GV001Program charter and mandatewhere writtenRecommendedInsider Threat Program Development ManualCoESS, co-financed by the Internal Security Fund of the European Union · read 11 Aug 2026The structure of an insider risk management program, as the closest thing to doctrine issued under European Union funding, unrevised since 2019.The Union-funded manual addresses how a program is structured, and states no legal basis for any of it.
MD001Threat modelling and detection scopingwhere writtenRecommendedENISA Threat Landscape 2020: Insider ThreatENISA · read 11 Aug 2026Attack vectors, incident findings, and mitigation at the level of general control categories, in the agency’s only thematic report on the subject.Scoping starts at the level of control categories rather than of tools, and the only Union report to work from stops there and dates from 2020.
MD008Access to the content of communicationswhere writtenRecommendedOpinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026That consent is rarely a valid ground in employment, and how legitimate interests are weighed against privacy across nine scenarios of workplace monitoring.The balance has to be struck before the content is opened, and it is struck differently for technology used outside the workplace than inside it.
MD013Physical access monitoringwhere writtenRecommendedSecure personal dataEuropean Data Protection Board · read 1 Sep 2026What controlling access to a building is taken to consist of, area by area, and what the Board says is owed before access to those areas is recorded.Where access to a room holding material whose loss would bear seriously on the people it concerns is recorded, two things are owed before it is: the people who handle the data are told the system exists, and the staff representatives are informed and consulted.
MD019Monitoring outside working hourswhere writtenRecommendedOpinion 2/2017 on data processing at work (WP249)Article 29 Data Protection Working Party · read 11 Aug 2026That consent is rarely a valid ground in employment, and how legitimate interests are weighed against privacy across nine scenarios of workplace monitoring.The balance covers technology used outside the workplace as well as inside it, so continuing after hours does not fall outside the assessment.