ISO 27001A.5 — Contact with authorities
A.5.5
Contact with authorities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Establish and maintain appropriate contacts with relevant authorities.
Points of focus
- Authorities relevant to scope identified
- Contact paths documented in IR / legal playbooks
- Triggers for notification understood
- Ownership with legal/compliance
Implementation notes
Maintain a living appendix of relevant authorities (e.g. local cybercrime units, privacy regulators where you have establishment or users, sector CERTs). Tie triggers to your incident severity model and GDPR/HIPAA clocks when those laws apply. Keep counsel in the loop — engineers should not freestyle regulatory notification. Review contacts annually and after geographic expansion.
Audit tip: Open the IR plan to the authority contacts page and show who owns the call decision.
Evidence auditors typically request:
- Authority contact list in IR plan appendix
- Legal retainer or counsel escalation path
- Breach notification decision tree referencing authorities
- Tabletop notes exercising notification
Common gaps
- Empty 'contact authorities' boilerplate with no names
- Engineering pages 911 without legal involvement
- EU/US authority mix-ups for multi-region SaaS
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.5 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.5)
Frequently Asked Questions
Yes at a proportionate level — at least law-enforcement and customer-contract notification paths. Add DPAs if you process EU personal data.
Related. A.5.5 is readiness to engage authorities; A.5.24–26 and legal articles cover incident handling and mandatory notices.
Counsel can own the list, but the IR plan must make the path discoverable under stress.