ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.5: Contact with authorities

The organization is to set up and keep up working contact with the authorities that are relevant to it. Purpose (stated in ISO/IEC 27002:2022): ensures information security information flows properly between the organization and legal, regulatory and supervisory authorities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.5.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 58 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

ISO 22301:2019 · 4 controls

  • 4.2.2 Legal and regulatory requirements
  • 7.4 Communication
  • 8.4.3 Warning and communication
  • 8.5 Exercise programme

NIS2 Directive · 4 controls

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.c Provide an intermediate report on status when the CSIRT or competent authority requests one
  • Art.3.4 Submit and maintain entity registration information with the competent authority
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

FedRAMP High · 3 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 3 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)

NIST SP 800-53 Rev 5 · 3 controls

  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days

C5 (Germany) · 2 controls

  • C5-INQ-01 Legal Assessment of Investigative Inquiries
  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups

DORA · 2 controls

EU AI Act · 2 controls

GDPR · 2 controls

  • GDPR-Art.31 Cooperation with the supervisory authority
  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

ISO/IEC 42001:2023 · 2 controls

  • A.8.3 External reporting
  • A.8.5 Information for interested parties

SOC 2 · 2 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • E8-APP-ML2 Application Control (ML2)

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • SEC10-BP01 Identify key personnel and external resources
  • SAFE-AEO-D Consultation, Co-operation and Communication

CIS Controls v8 · 1 control

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents

CMMC 2.0 · 1 control

ISO 27001:2013 · 1 control

ISO 27002:2022 · 1 control

  • 5.5 Contact with authorities

ISO 27018:2019 · 1 control

  • 6.1.3 Contact with authorities

ISO 27701:2019 · 1 control

  • 8.5.5 Legally binding PII disclosures

ISO/IEC 27010:2015 · 1 control

  • 27010-6.2 Contact with Authorities
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 7.1.a Article 7(1)(a): supply the Presidency with the data, information, documents, hardware and software it requests, with priority and on time

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.