Alessandro AleddaInsider Threat and Risk

Insider Threat Event Requirements (ITER)

What ITER is

Insider Threat Event Requirements (ITER™) is a living record of what an insider event obliges in Europe: the reporting acts, the term on each, whom it is owed to, and the point the term runs from.

types
5
acts
33
jurisdictions
32
sources
70
  • Type. The kind of insider event, and each kind sets off its own timeline: the obligations that run from the moment the organization is taken to know. Two events are the same type when they trigger the same obligations, or when the facts those obligations require are established by materially different means. An event can be more than one type; the record then carries the obligations of each, rather than choosing one.
  • Act. One reporting act that a regulation or directive obliges: what to do, whom it is owed to, the term, and the point the term runs from. Four Union instruments oblige the acts on this record, the General Data Protection Regulation (GDPR), the NIS2 Directive, the Digital Operational Resilience Act (DORA) and the Market Abuse Regulation (MAR), together with the national acts that transpose or apply them. Every act carries an identifier and the source it rests on, and a national act that moves a term or its anchor is recorded beside it.
  • Premise. A fact about the organization that every term depends on and no regulation states: whether the moment of knowledge is defined, who establishes it, and whether the investigation before it has a limit. The record sets the premises out ahead of the timeline, as they stand; what to do about them is the organization's own decision.

Set the event, the country and the kind of organization, and the page returns the acts that reach it: the term on each, the body it is owed to there, where the report is sent, and the premises every term depends on. It states what the regulations oblige an organization to do. It does not state what an organization should do with its own processes to meet them, it does not compare one jurisdiction with another, it does not grade an organization's readiness, and it is not advice on compliance.

Why ITER exists

ITER sets out one insider event in full: the timeline of what it obliges, and what has to be in place before it happens.

A security function has a plan for a confirmed incident: who declares it, who reports what, to whom, by when. An insider case strains that plan, for three reasons the framework sets out. Between early signs and confirmation there is an investigation, often extensive and confidential, and the terms keep running, because every term stated in hours runs from the moment the organization is taken to know, directly or through the act before it, and not from the moment it is sure.

The intervals are set by the instrument and are the same in every Member State. Every one of them runs from the point at which the organization is taken to know, directly or through the act before it, and no instrument defines that point: the European Data Protection Board (EDPB) sets a standard for it and leaves the organization to fix the evidence.

An organization that has not fixed it cannot say in advance when a term falls, or show afterwards the date it chose. ITER names that moment, states what each term is measured from, and sets out the premises every term depends on. It lets an organization hold its own plan against the timeline it does not choose, and see where the two part.

An event, end to endThe five screens of one case: the event, the jurisdiction, the organization, what reaches it, and when each act falls due. Each type opens its own.Through the framework
MapEvery jurisdiction on the record, with its recipients, its reporting address, and the state of the act that transposes NIS2.32 jurisdictions

Where it applies

Thirty-two jurisdictions in scope, and four Union instruments that bind in them.

The Member States of the European Union, the three states of the European Economic Area in which the Union's instruments apply, and two states in which they do not, the United Kingdom and Switzerland, where what binds instead is read as an equivalent. An act enters the record if it binds in one of those jurisdictions and sets a term, a recipient, or the point a term runs from, on an event an insider can cause.

A jurisdiction here is a state, because a report is owed to a body and the body sits in one. The Union and the Council of Europe are legal orders rather than states, and they issue what binds rather than receive what is reported, which is why a record of sources counts them and a record of reporting acts does not.

Every row states the evidence it rests on, and the evidence is taken from the kind of its sources, not decided row by row. Binding where the source is the act itself or a decided case. Reported where it is a register, or guidance from the body that applies the act. Provisional where it is an announcement, until an act or a case says the same. Unresolved where the source records no settled position. Where a row rests on more than one source, the weakest governs, because the mark says how far a row can be trusted, and a row is no more settled than its least settled source. INTRA's mark says how hard a row binds, and there the strongest governs. A row whose source has not been read, or is past the interval after which it is read again, says so in place of a mark.

Where to find the sources

Everything here is written in two files, and both are public.

The record and the library are kept as markdown in a repository, under a license that lets anyone use them and change them, and the data file this site reads is built from them. What is cited can be checked against what was published. The method both records are kept by is written once.

What is written down is 33 reporting acts, the recipients for 32 jurisdictions, and 70 sources, each carrying the date it was read and the interval after which it has to be read again. Across those jurisdictions the terms are the same; the recipients are not, and 12 of 30 national acts move a term or the point it runs from.

The record, in the openTwo markdown files and the build that turns them into this. Every row, every source, every date, in the form they are written in.33 acts  |  70 sources

Absences

What the record has looked for and not found, 3 things, is listed on the framework.

Version

11 SEPTEMBER 2026. 33 reporting acts across 5 worked types, resting on 70 sources, with recipients recorded for 32 jurisdictions. Every row carries the date its source was read, and every source the interval after which it has to be read again.

The record is two markdown files and the data file is built from them, so what is cited can be checked against what was published. Free to use under CC BY 4.0.

Schema 1.0, documented in SCHEMA.md, built from source commit b41f33e787.

Not computed

Durations are supplied by the reader. No default, no typical value, no benchmark and no maturity score: an interval this record has not read is an interval it does not state.

Whether the purpose of an access can be established is not computed either. It decides whether the people concerned must be told, and no instrument sets a term for answering it.

Contributing

ITER grows by contribution and debate. If a term is stated wrongly, if a jurisdiction has said something this does not record, or if a source belongs here and is missing, send me a message on LinkedIn. Contributors are named unless they ask not to be.

The people who have.

The record and the build are in the repository. INTRA™ and ITER™, Insider Threat and Risk Architecture and Insider Threat Event Requirements, are unregistered trade marks of Alessandro Aledda.