The organization is to set up and keep up working contact with the authorities that are relevant to it. Purpose: allow information security matters to pass properly between the organization and the legal, regulatory and supervisory bodies concerned. Guidance: the organization decides in which circumstances and by whom bodies such as law enforcement, regulators and supervisory authorities are contacted, and how confirmed information security incidents are reported to them promptly. These relationships are also a way to learn what the authorities expect now and plan to expect, for example forthcoming security regulations. Other information: an organization being attacked may ask authorities to act against the source; such contacts support incident management (5.24 to 5.28) and continuity (5.29 and 5.30), help anticipate legal change, and extend to utilities, emergency services, power, telecommunications and water providers and health and safety bodies such as fire services.
This control maps to 82 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
E8-ADMIN-ISM-0140 Restrict administrative privileges (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
E8-APP-ISM-0140 Application control (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
E8-MFA-ISM-0140 Multi-factor authentication (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
E8-UAH-ISM-0140 User application hardening (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.