ISO/IEC 27000 Information Security Event Reporting, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security event reporting.
Assessment Step
1
Information Security Event Reporting (InformationSecurityEventReporting)
Does the organization provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Information Security Event Reporting
The organization shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.
Citations
27001
Annex A, Control 6.8
27002
Section 6.8
|