ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.5: Contact with authorities

Keep working relationships with regulators, law enforcement and CERTs before you need them.

What else in your programme already covers this

This control maps to 65 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

ISO 22301:2019 · 4 controls

  • 4.2.2 Legal and regulatory requirements
  • 7.4 Communication
  • 8.4.3 Warning and communication
  • 8.5 Exercise programme

NIS2 Directive · 4 controls

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.c Provide an intermediate report on status when the CSIRT or competent authority requests one
  • Art.3.4 Submit and maintain entity registration information with the competent authority
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

FedRAMP High · 3 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 3 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-IR-6 Incident reporting
  • NIST800-PM-15 Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education and training for organizational personnel; To
  • NIST800-SI-5 Security alerts, advisories, and directives
  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)
  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)
  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives
  • SR-8 Notification Agreements (SR-8)
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days

C5 (Germany) · 2 controls

  • C5-INQ-01 Legal Assessment of Investigative Inquiries
  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups

DORA · 2 controls

EU AI Act · 2 controls

GDPR · 2 controls

  • GDPR-Art.31 Cooperation with the supervisory authority
  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

ISO/IEC 42001:2023 · 2 controls

  • A.8.3 External reporting
  • A.8.5 Information for interested parties

SOC 2 · 2 controls

  • SOC2-CC2.3 COSO principle 15: Communicates with external parties regarding matters affecting controls
  • SOC2-P6.6 Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • SEC10-BP01 Identify key personnel and external resources
  • SAFE-AEO-D Consultation, Co-operation and Communication

CIS Controls v8 · 1 control

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents

CMMC 2.0 · 1 control

ISO 27002:2022 · 1 control

  • 5.5 Contact with authorities

ISO 27018:2019 · 1 control

  • 6.1.3 Contact with authorities

ISO 27701:2019 · 1 control

  • 8.5.5 Legally binding PII disclosures

ISO/IEC 27010:2015 · 1 control

  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

PCI DSS 4.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 65 it maps to, and the evidence behind each claim, over MCP and REST.