ISO 27001A.6 — Information security event reporting
A.6.8
Information security event reporting
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.
Points of focus
- Published reporting channels
- Train people what to report
- Acknowledge and triage reports
- No retaliation for good-faith reports
Implementation notes
Publish one primary channel (ticketing or chat) and an after-hours path. Integrate email phishing report plugins. Feed reports into the incident process (A.5.24–A.5.26). Close the loop so reporters see outcomes.
Audit tip: Show training materials naming the channel plus three recent employee-originated tickets with triage timestamps.
Evidence auditors typically request:
- Security event reporting procedure
- Phishing report button metrics
- Ticket samples from employee reports
- Training completion covering reporting duty
Common gaps
- No known channel outside email to founders
- Reports sit unanswered
- Fear of blame after honest mistakes
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.8 | This control |
| SOC 2 | CC7.2, CC7.3 | Related SOC 2 themes (CC7.2, CC7.3) — map in your crosswalk; not identical requirements. |
| GDPR | Article 33 | Related GDPR themes (Article 33) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.308(a)(6) | Related HIPAA themes (§164.308(a)(6)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.8)
Frequently Asked Questions
Suspicious login, lost laptop, misdirected email with customer data, unexpected privilege change — when unsure, report.
Customer-facing security@ or trust page is separate; A.6.8 is primarily internal personnel.
Immediately for suspected compromise; define expectations in the procedure.
Even without owned data centers, information security event reporting still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with security event reporting procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.