Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Processes for reporting information security events related to offered cloud services

Critical
High
Normal
Low

When offering cloud services, the organisation needs to have planned processes or procedures for:

  • how the cloud service customer reports an information security event to the organisation
  • how the organisation reports information security events to cloud service customers
  • how the cloud service customer can track the status of a previously reported information security event
Connected other frameworks and requirements:
16: Information security incident management
ISO 27017
16.1: Information security incident and improvement management
ISO 27017
16.1.2: Reporting information security events
ISO 27017
ID.RA-3: Threat identification
NIST CSF
DE.DP-4: Event detection
NIST CSF

Keeping contact with relevant authorities

Critical
High
Normal
Low

The organization lists the relevant government actors with whom it is important to actively contact and, if necessary, get in touch quickly. These authorities include national law enforcement and supervisory authorities.

A clear contact person should be defined for the relevant authorities to act as a contact point for the organization.

Connected other frameworks and requirements:
6.1.3: Contact with authorities
ISO 27001
RC.CO-1: Public relations
NIST CSF
5.5: Contact with authorities
ISO 27001

Contact with industry-specific interest groups

Critical
High
Normal
Low

The organization shall actively maintain contacts with stakeholders relevant to the organization's operations and other relevant actors related to the organization's operations and security.

The goal is especially to:

  • increase knowledge of best practices and keep up to date with relevant security information
  • ensure that organisation's understanding of the security environment is up-to-date and complete
Connected other frameworks and requirements:
6.1.4: Contact with special interest groups
ISO 27001
ID.RA-2: Cyber threat intelligence
NIST CSF
RS.CO-5: Voluntary information sharing
NIST CSF
RC.CO-1: Public relations
NIST CSF
5.6: Contact with special interest groups
ISO 27001
No items found.