Skip to content
compliancebase
ISO 27001A.6 — Information security event reporting

A.6.8

Information security event reporting

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.

Points of focus

  • Published reporting channels
  • Train people what to report
  • Acknowledge and triage reports
  • No retaliation for good-faith reports

Implementation notes

Publish one primary channel (ticketing or chat) and an after-hours path. Integrate email phishing report plugins. Feed reports into the incident process (A.5.24–A.5.26). Close the loop so reporters see outcomes.

Audit tip: Show training materials naming the channel plus three recent employee-originated tickets with triage timestamps.

Evidence auditors typically request:

  • Security event reporting procedure
  • Phishing report button metrics
  • Ticket samples from employee reports
  • Training completion covering reporting duty

Common gaps

  • No known channel outside email to founders
  • Reports sit unanswered
  • Fear of blame after honest mistakes

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.8This control
SOC 2CC7.2, CC7.3Related SOC 2 themes (CC7.2, CC7.3) — map in your crosswalk; not identical requirements.
GDPRArticle 33Related GDPR themes (Article 33) — map in your crosswalk; not identical requirements.
HIPAA§164.308(a)(6)Related HIPAA themes (§164.308(a)(6)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Suspicious login, lost laptop, misdirected email with customer data, unexpected privilege change — when unsure, report.

Customer-facing security@ or trust page is separate; A.6.8 is primarily internal personnel.

Immediately for suspected compromise; define expectations in the procedure.

Even without owned data centers, information security event reporting still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with security event reporting procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above