This paper focuses on proposing a framework for security control that based on ISO 27001 and ISO 27002, which is a standard of Information Security Management System (ISMS). This framework helps to mitigate internal threats for data centre meant for public sector adoption. The ISMS implementation scope in the public sector normally comprises of data centre and information security services. Previous research indicates that there is no specific framework being develop to mitigate internal threat in the data centre. Findings from the previous study generally show that human resource security, access control, physical and environmental security, and operation and communication security are used to mitigate internal threats. Hence, this paper aims to identify the most important security elements to develop internal threats framework for data centre, as well as to formulate a guideline based on the identified elements. Finally, an internal threats framework based on the elements and the guidelines is developed. A qualitative research technique, such as an interview has been conducted to study the suitability of the identified security control elements. After the result of the first interview, a second interview is conducted to validate the proposed framework. A methodology used to establish the framework includes planning, analysis, design and validation. It is hoped that the establishment of the framework, may guide the public sector to manage internal threats for the data centre, as well as to reduce security incidents which may cause by human factors