ISO 27002:2022
People controls – ISO 27002:2022

ISO 27002:2022 6.8: Information security event reporting

A mechanism is to be provided so personnel can report information security events they notice or suspect, promptly and through the right channels. Purpose: support reporting of events that personnel can spot in a timely, consistent and effective way. Guidance: all personnel and users should know they must report events as fast as possible so incidents can be prevented or their effects limited, and should know the reporting procedure and the contact point. The mechanism should be as simple, accessible and available as possible. Events include incidents, breaches and vulnerabilities, and situations worth reporting include controls that do not work, breaches of expected confidentiality, integrity or availability, human error, non-compliance with policies or standards, physical security breaches, system changes that bypassed change management, software or hardware malfunctions and anomalous behaviour, access violations, vulnerabilities and suspected malware. People should be told not to try to prove a suspected vulnerability, because testing it can look like misuse, can damage systems or services, can spoil or hide digital evidence and can expose the tester to legal liability. See the ISO/IEC 27035 series.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 71 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 5.36 Compliance with policies, rules and standards for information security
  • 6.8 Information security event reporting

ACSC Essential Eight · 5 controls

  • E8-APP-ML2 Application Control (ML2)
  • E8-ADMIN-ISM-0123 Restrict administrative privileges (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-APP-ISM-0123 Application control (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-MFA-ISM-0123 Multi-factor authentication (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-UAH-ISM-0123 User application hardening (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered

FedRAMP High · 5 controls

  • AT-2(2) Insider Threat
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-7 Incident Response Assistance
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))

FedRAMP Moderate · 5 controls

  • AT-2(2) Insider Threat
  • IR-6 Incident Reporting
  • IR-6(1) Automated Reporting
  • IR-7 Incident Response Assistance
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))

SOC 2 · 5 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring
  • ISM-0123 Reporting incidents to the CISO
  • ISM-0142 Reporting cryptographic equipment compromise
  • ISM-0817 Reporting suspicious contact via online services
  • ISM-1088 Reporting potential mobile device compromise

CIS Controls v8 · 3 controls

  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

CMMC 2.0 · 2 controls

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security
  • 7.2.17.C.02 7.2.17.C.02 Reporting weaknesses, malfunctions and quantifying incidents
  • 7.3.7.C.03 7.3.7.C.03 SOP procedures for reporting spills and unauthorised access

PCI DSS 4.0 · 2 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-27 Identification and Escalation of Incidents and Near Misses

APRA CPS 234 · 1 control

  • AEO-10 Education, Training and Awareness
  • ASBv3-IR-2 Preparation - setup incident notification

C5 (Germany) · 1 control

  • C5-SIM-04 Duty of the users to report security incidents to a central body

DORA · 1 control

  • s77 s 77 Be able to receive confidential reports of data protection violations

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 42001:2023 · 1 control

  • A.3.3 Reporting of concerns

NIS2 Directive · 1 control

  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance

NIST SP 800-172 · 1 control

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 6.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.