Alessandro AleddaInsider Threat and Risk

INTRA/NONorway

What the record establishes for Norway, measure by measure, and what each source requires of the measure it governs.

Binding
14
Recommended
9
Reported
0
Measures touched
21 of 110
Sources cited
3
ControlSourceWhat it establishesPrerequisite or recommendation
14Mandatory
AW002/NOTransparency notice on what is observedMandatoryArbeidsmiljøloven, sections 9-1 and 9-2Storting · read 29 Aug 2026That a control measure needs objective grounds in the undertaking and must not be a disproportionate burden, and that it is discussed with the elected representatives, notified with its expected duration, and evaluated with them at intervals.Before the measure starts, those affected are told its purpose, what it will mean in practice, how it will be carried out, and how long it is expected to last.
DP011/NORetention and disposal of business recordsMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.What is left in the mailbox and in the worker’s own areas, and is not necessary for the daily running of the undertaking, is deleted within a reasonable time of the employment ending.
DP012/NORetention and disposal of program recordsMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.What is opened and proves not to be necessary or relevant to the purpose is closed at once, and any copy of it deleted.
DP014/NOPersonal material in company accountsMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.The worker’s personal areas on the undertaking’s network and equipment are reached on the same conditions as the mailbox, and so is what was deleted from them and survives on a backup.
GV007/NOLawful basis registerMandatoryArbeidsmiljøloven, sections 9-1 and 9-2Storting · read 29 Aug 2026Forskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026That a control measure needs objective grounds in the undertaking and must not be a disproportionate burden, and that it is discussed with the elected representatives, notified with its expected duration, and evaluated with them at intervals.A control measure rests on objective grounds in the circumstances of the undertaking and must not be a disproportionate burden on the person subject to it. No instruction and no agreement may depart from that to the worker’s detriment, so an agreement cannot be the ground for reaching further.
GV010/NOWorker representative engagementMandatoryArbeidsmiljøloven, sections 9-1 and 9-2Storting · read 29 Aug 2026That a control measure needs objective grounds in the undertaking and must not be a disproportionate burden, and that it is discussed with the elected representatives, notified with its expected duration, and evaluated with them at intervals.The need for the measure, its design, its implementation, and any material change to it are discussed with the elected representatives as early as possible.
GV013/NOPeriodic program reviewMandatoryArbeidsmiljøloven, sections 9-1 and 9-2Storting · read 29 Aug 2026That a control measure needs objective grounds in the undertaking and must not be a disproportionate burden, and that it is discussed with the elected representatives, notified with its expected duration, and evaluated with them at intervals.The need for the measures is evaluated at intervals, and the evaluation is made together with the elected representatives rather than by the employer alone.
IV005/NOForensic acquisitionMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.The access is carried out so that the data are so far as possible not altered, and so that what it produced can be checked afterwards.
IV010/NODecision recordMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.The written notice states the method of access used, which messages or documents were opened, and what the access found.
MD005/NONetwork and egress monitoringMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.Monitoring a worker’s use of electronic equipment, internet use included, is not open to the employer at all unless the purpose is administering the network or detecting and resolving a security breach in it.
MD006/NOElectronic mail and collaboration monitoringMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.The mailbox provided for the work is reached only where it is necessary for daily operations or another legitimate interest, or on reasonable suspicion of a gross breach of the duties of the employment or of grounds for dismissal. The same holds for what was deleted from it and survives on a backup.
MD008/NOAccess to the content of communicationsMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.Where it is possible the worker is told first, given the chance to comment, and allowed to be present with a representative of their choosing. Where it was not possible, they are told in writing once the access is done.
MD009/NORetention of web and network activity recordsMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.A record of what the worker reached may be kept where the purpose is administering the network or detecting and resolving a security breach in it, the regulation putting other purposes outside what the employer may do.
PS008/NOLeaver processMandatoryForskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around.The mailbox is closed when the employment ends, and stays open only where there is a particular need and only for a short period.
9Recommended
AW001Workforce awareness on insider riskwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.Real cases from the handling of incidents are to be used in the training and the raising of awareness of staff, and the results of an evaluation are shared with those they concern.
AW002Transparency notice on what is observedwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.The workforce is informed of what is collected, what it is to be used for, and how the data are to be handled, and that sits alongside establishing which laws apply and deciding how long the data shall and may be stored.
DP012Retention and disposal of program recordswhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.The security relevant data are to be used only to safeguard the security of the systems, and kept long enough that unwanted activity can be discovered and mapped after the fact. What weighs on the period is that the data may later be wanted for an investigation, for assessing damage, and for trend analysis, held against the point that they can hold confidential information about the individual employee.
IR009Post-incident reviewwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.What worked and what can be improved are both identified. The controls that were compromised are mapped and reviewed and then updated or replaced, and it is assessed whether what is in place covers the organization’s risk picture at all. The processes, procedures, reporting formats, and organizational structures are evaluated for how effective they were, regularly and after an incident.
MD002Log collection and centralizationwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.A written strategy for security monitoring settles the purpose and the field of use of what is collected, which data are collected, their secure storage including for legal proceedings, capacity planning, who may reach them, the consolidation of logs from the different units and services, deletion, and the interval at which the strategy is reviewed, at least once a year and after a major incident. What is collected is verified against what was meant to be, the data are archived and digitally signed at intervals for integrity, functionality is put in place that detects attempts to alter or delete a log, everything is synchronized to one and the same time source, and what has lost its operational or security relevance is removed.
MD003Detection use case developmentwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.Tools are taken into use that allow manual and automatic searching and alerting on criteria across everything collected, and that assemble data from different sources on their own so that it can be decided whether the event is real rather than a false positive, and what its extent and character are. Knowledge of the normal state and of the threats is what the searches and the alerting criteria are improved from.
MD012User and entity behavior analyticswhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.Knowledge of the normal state of the systems is established and maintained so that a change or an abnormality pointing to unauthorized action can be seen. The maintenance is the requirement: the normal state has to answer to reorganizations, acquisitions, mergers, downsizing, and a change of operating concept. What it is meant to expose is named as data flowing against the flow that was decided, data flowing at abnormal times, and abnormally large volumes.
MD020Alert triage and case creationwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.The log data are gone through and the relevant data about the event gathered to give a decision a basis, which may mean assembling data from several sources or running tests to confirm or rule out an event. The severity is then settled against the plan laid down in advance: whether it is a possible or a confirmed security incident or a false alarm, its class under the classification regime, which roles are brought in, and whether the contingency plan is triggered.
MD021Detection coverage assessmentwhere writtenRecommendedNSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working.It is verified that the collection works as it was meant to. The log settings are checked to see that they function and that what was to be gathered is being gathered, every system that regularly stores security relevant data is given enough space that nothing needed is lost, and a standardized format is used so the data can be read by a third party’s analysis tool.