The organization shall communicate event detection information to predefined parties.
Guidance
Event detection information includes for example, alerts on atypical account usage, unauthorized remote access, wireless connectivity, mobile device connection, altered configuration settings, contrasting system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, use of Voice over Internet Protocol (VoIP), and malware disclosure.
When offering cloud services, the organisation needs to have planned processes or procedures for:
The organization has an operating model for regular communication to the entire organization about the risk situation in information security and about new significant risks affecting the organization.
Information can be implemented, for example, as a collaboration between the information security core team and communication professionals.
The organization has defined procedures to ensure that the original reporter and other personnel involved in the incident are informed of the outcome of the incident management.
Linked personnel can be documented on an optional field on the incident documentation template.