Alessandro AleddaInsider Threat and Risk

INTRA/ITItaly

What the record establishes for Italy, measure by measure, and what each source requires of the measure it governs.

Binding
43
Recommended
0
Reported
0
Measures touched
43 of 110
Sources cited
9
ControlSourceWhat it establishesPrerequisite or recommendation
43Mandatory
AW001/ITWorkforce awareness on insider riskMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, a training plan for the workforce, the administrative and management bodies included, is defined, implemented, kept current, and documented, and those bodies approve it. It sets out what is taught and, where any are provided for, how it is checked that the content was taken in. What it teaches is the security of systems, not insider risk.
AW002/ITTransparency notice on what is observedMandatoryProvvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That mailbox backups and browsing logs are instruments from which remote monitoring may follow, that an answer given in stages and handed over in part without saying what was withheld does not discharge the right of access, and that a five year backup of employee mail has to be disclosed to the people whose mail it holds.A backup of the mailboxes described in none of the notices given to the staff leaves them unable to know it exists, which is the finding rather than the keeping itself.
AW003/ITRole-specific trainingMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For an essential subject, training dedicated to the people in specialized roles, system administrators named among them, is part of the same plan, and it covers the secure configuration and operation of the systems, the threats that are known, and what to do when an event bearing on security occurs.
AW004/ITTraining recordsMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, an up-to-date register is kept of the employees who received the training, of its contents, and of the checks carried out where checks were provided for. A register of the same kind is required for the training given to specialized roles.
CP004/ITReliance on material obtained in breachMandatorySentenza n. 24204/2025Corte di Cassazione, Labour Section · read 11 Aug 2026That personal correspondence keeps its protection on company systems, and that what is taken from it cannot be relied on in proceedings.Material taken from personal correspondence could not be relied on, the Strasbourg case law being applied in the national setting.
DP004/ITAccess control and least privilegeMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, permissions are assigned on least privilege, separation of functions, and need to know. How an account authenticates is set against the risk, weighed on the privileges it holds, the criticality of the systems, and the kind of operations it can perform on them, and multi-factor authentication is used on the systems that matter.
DP005/ITPrivileged access managementMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, every account is inventoried and approved by someone inside the organization, those with administrative privileges and those used for remote access included, and accounts are individual to a user unless there is a documented technical reason otherwise. A system administrator’s privileged and unprivileged accounts are to be completely distinct, and to carry different credentials.
DP006/ITAccess recertificationMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, accounts and the authorizations on them are verified periodically on the systems that matter, and updated or revoked where a change calls for it.
DP007/ITData loss prevention deploymentMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the loss prevention capability.
DP011/ITRetention and disposal of business recordsMandatoryProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026Provvedimento n. 364, guidance document on email metadata in the workplaceGarante per la protezione dei dati personali · read 11 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Twenty-one days is the outer limit for email metadata before the article 4 route is engaged, and ninety days of it alongside browsing logs has drawn a fine. A five year backup of everything passing through the mailboxes, kept to preserve the information estate, was held unlawful where no notice given to the staff described it.
DP014/ITPersonal material in company accountsMandatoryProvvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That mailbox backups and browsing logs are instruments from which remote monitoring may follow, that an answer given in stages and handed over in part without saying what was withheld does not discharge the right of access, and that a five year backup of employee mail has to be disclosed to the people whose mail it holds.A former worker retains a claim on personal material left in the account, and the employer has to be able to answer a request for access to it.
GV004/ITRoles and decision rightsMandatoryProvvedimento del 17 aprile 2026, Framos ItaliaGarante per la protezione dei dati personali · read 29 Aug 2026That a company mailbox left running after the employment ends is a processing needing a ground of its own, and that a smooth handover and the chance of wanting something later are not one.The technician who reached into the accounts held the role and not the instruction. A signed confidentiality undertaking is not the documented instruction the Regulation asks of anyone processing on the controller’s behalf.
GV008/ITImpact assessment before deploymentMandatoryProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Its absence is enough on its own: a decision has turned on the missing procedural steps without reaching the purpose the processing served.
GV010/ITWorker representative engagementMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.The body brought in is the union representation, and its agreement is the condition on which any instrument capable of remote monitoring may exist at all.
GV014/ITAnswering a request from the personMandatoryProvvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That mailbox backups and browsing logs are instruments from which remote monitoring may follow, that an answer given in stages and handed over in part without saying what was withheld does not discharge the right of access, and that a five year backup of employee mail has to be disclosed to the people whose mail it holds.Answering in stages across five months, and then handing over the correspondence purged of many elements without saying what had been taken out or why, was held not to be an answer.
IR001/ITInsider incident playbooksMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, a plan for handling incidents and notifying the national CSIRT is defined, implemented, kept current, and documented, and it carries the stages and the procedures with the roles and responsibilities attaching to each, the contacts for reporting, how communication runs inside and outside, and the reporting to be used to document the incident. The management bodies approve it. That the scenarios it covers include insider ones is not stated.
IR006/ITNotification to a supervisory authorityMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, the plan carries the procedures for preparing and sending the reports the NIS decree requires, and it names the contacts through which an incident is reported. Notification runs to CSIRT Italia.
IR007/ITNotification to affected personsMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.Procedures are documented for telling the recipients of a service, without unjustified delay, of a significant incident that may bear adversely on the provision of that service, and for telling those exposed to a significant threat what its nature is and what they can do about it. Separate procedures cover informing the public where the agency orders it.
IR008/ITEscalation to crisis managementMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, how communication runs inside the organization is part of the plan, and the involvement of the administrative and management bodies is named as part of it. Those bodies approve the plan itself.
IR009/ITPost-incident reviewMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, the plan is reviewed and where appropriate updated periodically and in any case at least every two years, and again whenever a significant incident occurs, with the lessons learned from it worked in.
IV008/ITUse of records held for other purposesMandatoryProvvedimento n. 107, Amazon Italia LogisticaGarante per la protezione dei dati personali · read 16 Aug 2026That records of illness, union activity, and family circumstances kept by managers had no lawful basis, and attract the stricter regime.Records held by line management are the same material by another route: reaching into them needs the ground the monitoring system would have needed.
MD002/ITLog collection and centralizationMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, all remote access and all access made with administrative privileges are recorded. For the systems that matter, the logs needed to monitor security events are acquired and kept securely and, where it can be done, centrally, and how long they are kept is fixed from the risk assessment and documented.
MD003/ITDetection use case developmentMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, qualitative and quantitative parameters for detecting unauthorized access, or access abusing the privileges granted, are defined, monitored, and documented. The requirement is on essential subjects, and the same annexes do not place it on important ones.
MD004/ITEndpoint activity monitoringMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the endpoint agent.
MD005/ITNetwork and egress monitoringMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the traffic inspection.
MD006/ITElectronic mail and collaboration monitoringMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the recording of the messaging platform.
MD007/ITRetention of communications metadataMandatoryProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026Provvedimento n. 364, guidance document on email metadata in the workplaceGarante per la protezione dei dati personali · read 11 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Twenty-one days is the outer limit before the article 4 route is engaged, and the limit reaches the envelope only: parties, times, size, and routing.
MD008/ITAccess to the content of communicationsMandatorySentenza n. 24204/2025Corte di Cassazione, Labour Section · read 11 Aug 2026That personal correspondence keeps its protection on company systems, and that what is taken from it cannot be relied on in proceedings.What is taken from personal correspondence on a company system cannot be relied on afterwards, so opening it forecloses the use of what it yields.
MD009/ITRetention of web and network activity recordsMandatoryProvvedimento n. 243Garante per la protezione dei dati personali · read 11 Aug 2026Provvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That ninety days of metadata and browsing logs, kept without the procedural steps, draws a fine, the reasoning turning on the steps and not the purpose.Browsing logs are an instrument from which remote monitoring may follow, so retaining them engages the article 4 route as metadata does.
MD010/ITMailbox and file store imagingMandatoryProvvedimento n. 165, ITAS MutuaGarante per la protezione dei dati personali · read 16 Aug 2026That mailbox backups and browsing logs are instruments from which remote monitoring may follow, that an answer given in stages and handed over in part without saying what was withheld does not discharge the right of access, and that a five year backup of employee mail has to be disclosed to the people whose mail it holds.Holding a mailbox as a whole engages the article 4 route in the same way as retaining the traffic around it, and a former holder retains a claim on what is personal in it.
MD011/ITPrivileged session recordingMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the session recorder.
MD012/ITUser and entity behavior analyticsMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the analytics engine.
MD013/ITPhysical access monitoringMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the access-control recording.
MD014/ITVideo surveillance of the workplaceMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the cameras.
MD015/ITGeolocation of vehicles and devicesMandatorySentenza n. 3462/2026Corte di Cassazione, First Section · read 16 Aug 2026That vehicle tracking is processing of worker data wherever the driver can be identified, including indirectly.Tracking requires notification to the supervisory authority wherever the driver can be identified, and identification through vehicle assignment is enough.
MD016/ITMeasurement of pace and performanceMandatoryLegge 20 maggio 1970, n. 300, article 4Parliament of Italy · read 11 Aug 2026That an instrument from which remote monitoring may follow is permitted only for stated purposes, and only after a union agreement or an authorization.An agreement with the union representatives, or failing that an authorization from the labor inspectorate, is required before installing the measurement.
PS001/ITPre-employment screeningMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, the people authorized to reach the systems that matter are identified on a prior assessment of experience, capability, and trustworthiness, and have to give suitable guarantee that they will keep to the rules on information security. The trustworthiness of human resources is one of the areas the determination requires a written policy to cover.
PS003/ITScreening of privileged-role holdersMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, system administrators are a category of their own. They are identified on the same prior assessment of experience, capability, and trustworthiness, stated in a requirement separate from the one covering everyone else admitted to the systems that matter.
PS007/ITRole change and internal transferMandatoryDeterminazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter.For a subject in the national NIS register, accounts and the authorizations on them are verified periodically on the systems that matter, and updated or revoked when something changes. A transfer of personnel is named as such a change, alongside the end of an employment.
PS008/ITLeaver processMandatoryProvvedimento del 17 aprile 2026, Framos ItaliaGarante per la protezione dei dati personali · read 29 Aug 2026Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026That a company mailbox left running after the employment ends is a processing needing a ground of its own, and that a smooth handover and the chance of wanting something later are not one.Leaving the account running after the employment ends is itself a processing and needs a ground of its own. Telling correspondents the person has gone, and keeping what may be wanted later, are not grounds, and running past the period the employer itself declared counts against it. Separately, obligations in the field of information security that stay valid after the employment ends, or changes, are fixed at the contractual level, confidentiality clauses among the examples given, on essential subjects.
PS010/ITLine management records of personal circumstancesMandatoryProvvedimento n. 107, Amazon Italia LogisticaGarante per la protezione dei dati personali · read 16 Aug 2026That records of illness, union activity, and family circumstances kept by managers had no lawful basis, and attract the stricter regime.Notes kept by managers about a worker’s circumstances are processing like any other: outside a declared purpose and a lawful ground they have neither.
PS011/ITRecords concerning trade union activityMandatoryProvvedimento n. 107, Amazon Italia LogisticaGarante per la protezione dei dati personali · read 16 Aug 2026That records of illness, union activity, and family circumstances kept by managers had no lawful basis, and attract the stricter regime.A record touching union membership or activity falls in the stricter category, whatever the file it sits in and whoever wrote it.
PS012/ITRecords concerning health held for security purposesMandatoryProvvedimento n. 107, Amazon Italia LogisticaGarante per la protezione dei dati personali · read 16 Aug 2026That records of illness, union activity, and family circumstances kept by managers had no lawful basis, and attract the stricter regime.A record of absence or illness held for the program falls in the stricter category, and holding it for security purposes does not move it out.