Alessandro AleddaInsider Threat and Risk

INTRA/NLNetherlands

What the record establishes for the Netherlands, measure by measure, and what each source requires of the measure it governs.

Binding
12
Recommended
13
Reported
0
Measures touched
25 of 110
Sources cited
2
ControlSourceWhat it establishesPrerequisite or recommendation
12Mandatory
DP007/NLData loss prevention deploymentMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before the arrangement bringing the loss prevention capability in is adopted.
DP008/NLData loss prevention policy and tuningMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.Consent is owed on the arrangement being amended and on its being withdrawn, not only on its adoption, so the rules cannot be revised around the works council.
GV010/NLWorker representative engagementMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The body brought in is the works council, and its consent is required for the arrangement itself, not only for the instrument under it.
MD004/NLEndpoint activity monitoringMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the endpoint agent is adopted, amended, or withdrawn.
MD005/NLNetwork and egress monitoringMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the traffic inspection is adopted, amended, or withdrawn.
MD006/NLElectronic mail and collaboration monitoringMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the recording of the messaging platform is adopted, amended, or withdrawn.
MD011/NLPrivileged session recordingMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the session recorder is adopted, amended, or withdrawn.
MD012/NLUser and entity behavior analyticsMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the analytics engine is adopted, amended, or withdrawn.
MD013/NLPhysical access monitoringMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the access-control recording is adopted, amended, or withdrawn.
MD014/NLVideo surveillance of the workplaceMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the cameras is adopted, amended, or withdrawn.
MD015/NLGeolocation of vehicles and devicesMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the tracking device is adopted, amended, or withdrawn.
MD016/NLMeasurement of pace and performanceMandatoryWet op de ondernemingsraden, article 27(1)(l)Staten-Generaal · read 16 Aug 2026Consent of the works council for an arrangement directed at or merely suitable for observing presence, conduct, or performance.The works council has to consent before any arrangement governing the measurement is adopted, amended, or withdrawn.
13Recommended
AW001Workforce awareness on insider riskwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Everyone using the information systems, employees and contractors alike, has demonstrably completed an awareness training within three months of entering service. Management is to press the importance of it at appointment and at an internal transfer, and in work meetings and personnel discussions, and to encourage it being taken again periodically.
AW004Training recordswhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.The completion of the awareness training within three months of entering service has to be demonstrable, which puts the record of who took it and when inside the requirement.
DP005Privileged access managementwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Only authorized personnel reach the system utilities, and only at the moments when reaching them is strictly necessary. Their use is logged, and the log is available for examination for half a year.
DP006Access recertificationwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Every access right that has been issued is assessed at least once a year.
GV006Escalation triggers and ownerswhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.The monitoring process in the security operations function has unambiguous rules about when an incident is reported to the management answerable for it.
IV001Internal reporting channelwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Everyone, internal and external, has demonstrably taken notice of the procedure for reporting an information security incident.
IV007Legal hold and preservationwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.An incident and everything needed to analyze and resolve it are kept for at least three years, and what that covers is named: the logging, the resolution, and the advice given.
MD002Log collection and centralizationwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.There is an overview of the log files that are generated. How long the log files and the data in the security information and event monitoring are kept is settled against the risk, and the scenario it is settled against is named: that the attackers have been inside for a long time. Improper alteration or deletion of log data, and any attempt at it, is reported as soon as it can be.
MD003Detection use case developmentwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Use cases for the misuse of authentication data are defined, monitored, and acted on, and two of them are named in the text: logins from unusual places, and spikes in failed login attempts. Separately, the creation and modification of accounts carrying special rights is monitored, and where such a change was not authorized it is an information security incident and is recorded and handled as one.
PS001Pre-employment screeningwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Every entity has a screening policy that has been settled. On entering service, and on a change of function, a certificate of conduct may be asked for on the basis of a weighing of the risk.
PS002Risk-tiered screening standardswhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.The certificate of conduct is asked for on a weighing of the risk rather than as a matter of course, so what sets the depth is the assessment and not the grade of the post.
PS006Onboarding security briefingwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.Everyone, internal and external, is pointed to their responsibilities for information security on appointment or on a change of function, and the rules and instructions that apply to them are to be simple to reach.
PS007Role change and internal transferwhere writtenRecommendedBaseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time.A change of function is one of the two occasions on which the certificate of conduct may be asked for, the other being entry into service.