ISO 27002:2022 6.8: Information security event reporting
A mechanism is to be provided so personnel can report information security events they notice or suspect, promptly and through the right channels. Purpose: support reporting of events that personnel can spot in a timely, consistent and effective way. Guidance: all personnel and users should know they must report events as fast as possible so incidents can be prevented or their effects limited, and should know the reporting procedure and the contact point. The mechanism should be as simple, accessible and available as possible. Events include incidents, breaches and vulnerabilities, and situations worth reporting include controls that do not work, breaches of expected confidentiality, integrity or availability, human error, non-compliance with policies or standards, physical security breaches, system changes that bypassed change management, software or hardware malfunctions and anomalous behaviour, access violations, vulnerabilities and suspected malware. People should be told not to try to prove a suspected vulnerability, because testing it can look like misuse, can damage systems or services, can spoil or hide digital evidence and can expose the tester to legal liability. See the ISO/IEC 27035 series.
This control maps to 71 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-ADMIN-ISM-0123 Restrict administrative privileges (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
E8-APP-ISM-0123 Application control (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
E8-MFA-ISM-0123 Multi-factor authentication (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
E8-UAH-ISM-0123 User application hardening (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 6.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.