Determine which primary and secondary mechanisms will be used to communicate and report
during a security incident. Mechanisms can include phone calls, emails, secure chat, or notification
letters. Keep in mind that certain mechanisms, such as emails, can be affected during a security
incident. Review annually, or when significant enterprise changes occur that could impact
this Safeguard.
The organisation should have clear communication channels for event reporting:
Organisation should also consider the possibility of external reporting. This could mean having a system to handle security event reports from external parties, including:
The organisation should also ensure that the mechanisms and information for reporting incidents are easily accessible to all relevant reporters and establish a feedback procedure to provide timely responses and updates to those who report security events, ensuring they are informed of the outcomes and any necessary follow-up actions.