← ISO 27001 · A.6 — People

A.6.8 — Information security event reporting

medium incident-responseawareness

Requirement

The organisation shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
reportreporting
Required element 2 — any one of
security eventincidentsuspiciousphishing
Supporting terms — specificity signals
channelemail aliasslackhotlineno blamehow to report

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.33 Notification of a breach to the supervisory authority incident-response
SOC 2 CC7.3 Evaluation of security events incident-response
SOC 2 CC7.4 Incident response programme incident-response
SOC 2 CC7.5 Recovery from identified incidents incident-response
PCI DSS 4.0.1 5.4.1 Protection against phishing awareness
PCI DSS 4.0.1 10.7 Failures of critical security controls are detected and addressed incident-response
PCI DSS 4.0.1 12.6 Security awareness programme awareness
PCI DSS 4.0.1 12.10 Incident response plan for suspected compromise of account data incident-response