Contact with authorities
Purpose
Ensure information flows appropriately between the organisation and relevant legal, regulatory and supervisory authorities.
How to meet this control
In short: Maintain contact with relevant authorities (regulators, law enforcement).
- Step 01Build an authority contact list naming the relevant bodies (the OAIC for privacy breaches, the ACSC, state police, ASIC or APRA where applicable) with current phone numbers and portals
- Step 02Document inside the incident response plan exactly who contacts which authority, the trigger and the timeframe (for example the OAIC notifiable data breach scheme)
- Step 03Pre-register for relevant reporting portals such as ReportCyber so accounts exist before an incident
- Step 04Track regulatory expectations gathered through these contacts and feed updates into the compliance obligations register
- Step 05Review and re-verify the contact list at least annually and after any regulatory change
Tip: List who calls which authority during an incident, with numbers, in your IR plan.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Decide in advance when and by whom authorities should be contacted
- ›Identify the relevant authorities such as law enforcement, regulators and supervisory bodies
- ›Define how and how quickly security incidents are reported to those authorities
- ›Use these contacts to stay informed about current and upcoming regulatory expectations
- ›Maintain contacts that support incident response and business continuity planning
- ›Include other useful contacts like emergency services, utilities and telecommunication providers
- ›Where under attack, be ready to request that authorities act against the attack source
Audit evidence to keep
- - Authority contact register with named bodies, contacts and reporting channels
- - Incident response plan section defining authority notification triggers and timeframes
- - Evidence of registration with relevant reporting portals (for example ReportCyber)
- - Records of any actual regulatory notifications or correspondence
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.5. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.