ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.5: Contact with authorities

The organization is to set up and keep up working contact with the authorities that are relevant to it. Purpose: allow information security matters to pass properly between the organization and the legal, regulatory and supervisory bodies concerned. Guidance: the organization decides in which circumstances and by whom bodies such as law enforcement, regulators and supervisory authorities are contacted, and how confirmed information security incidents are reported to them promptly. These relationships are also a way to learn what the authorities expect now and plan to expect, for example forthcoming security regulations. Other information: an organization being attacked may ask authorities to act against the source; such contacts support incident management (5.24 to 5.28) and continuity (5.29 and 5.30), help anticipate legal change, and extend to utilities, emergency services, power, telecommunications and water providers and health and safety bodies such as fire services.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 82 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

ACSC Essential Eight · 5 controls

  • E8-APP-ML2 Application Control (ML2)
  • E8-ADMIN-ISM-0140 Restrict administrative privileges (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
  • E8-APP-ISM-0140 Application control (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
  • E8-MFA-ISM-0140 Multi-factor authentication (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
  • E8-UAH-ISM-0140 User application hardening (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered

NIST SP 800-53 Rev 5 · 5 controls

  • Art. 14(1) Notifying actively exploited vulnerabilities to the CSIRT and ENISA
  • Art. 14(2)(a) Early warning within 24 hours of awareness of an exploited vulnerability
  • Art. 14(2)(b) Vulnerability notification within 72 hours
  • Art. 14(2)(c) Final report on the exploited vulnerability within 14 days of a fix

NIS2 Directive · 4 controls

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.c Provide an intermediate report on status when the CSIRT or competent authority requests one
  • Art.3.4 Submit and maintain entity registration information with the competent authority
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
  • 9 9 The role of law enforcement
  • 9.1 9.1 Law enforcement intervention
  • A.3.1.3.1 A.3.1.3.1 Liaise with first responders

APRA CPS 234 · 3 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • 35 Para 35 Notify APRA of material incidents within 72 hours

ISO 22301:2019 · 3 controls

  • 4.2.2 Legal and regulatory requirements
  • 7.4 Communication
  • 8.4.3 Warning and communication
  • TSA-SD-02 Cybersecurity incident reporting to CISA
  • TSA-SD-15 Annual Cybersecurity Assessment report submission
  • TSA-SD-17 Cybersecurity Coordinator update notifications

TSA Pipeline Security · 3 controls

  • TSA-PSG-06 Pipeline right of way and onshore security
  • TSA-PSG-10 Security incident response
  • TSA-PSG-15 Communication and coordination with stakeholders
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours
  • PROC.BREACH Report data breaches to the ATO within one business day
  • PROC.CHANGE Notify the DPO of significant changes to the business or product
  • ISM-0140 Reporting incidents to ASD
  • ISM-0597 Consulting ASD on Cross Domain Solutions

DORA · 2 controls

FedRAMP High · 2 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 2 controls

  • IR-6 Incident Reporting
  • SI-5 Security Alerts, Advisories, and Directives

GDPR · 2 controls

  • GDPR-Art.31 Cooperation with the supervisory authority
  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • 0017 0017 Dedicated, monitored security email address
  • 0028 0028 Report significant and externally reportable incidents within timeframes

SOC 2 · 2 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SEC10-BP01 Identify key personnel and external resources
  • SAFE-AEO-D Consultation, Co-operation and Communication

C5 (Germany) · 1 control

  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups

CIS Controls v8 · 1 control

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents

CMMC 2.0 · 1 control

ISO 19011:2018 · 1 control

  • 6.4 Conducting audit activities

ISO 27001:2022 · 1 control

  • 5.5 Contact with authorities

ISO 27018:2019 · 1 control

  • 6.1.3 Contact with authorities

ISO 27701:2019 · 1 control

ISO/IEC 27010:2015 · 1 control

  • 27010-6.2 Contact with Authorities

ISO/IEC 27043:2015 · 1 control

  • ISO27043-05 Contact with authorities and special interest groups

ISO/IEC 42001:2023 · 1 control

ISO/SAE 21434 · 1 control

  • ISO21434-05 Contact with authorities and special interest groups

MTCS (Singapore) · 1 control

  • 6.8 Information security liaisons (ISL)
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

NIST SP 800-218 · 1 control

NY DFS 23 NYCRR 500 · 1 control

  • MTSA-Incident-Reporting Reporting of Breaches of Security and Suspicious Activity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 82 it maps to, and the evidence behind each claim, over MCP and REST.