Contact with Authorities

What is Contact with Authorities?

What is Contact with Authorities?

Having a plan for talking to outside groups like the police or government agencies. This helps your company know what to do if there’s a security problem. It ensures you share the right information with the right people at the right time.

Examples

  • Cybercrime: If hackers steal customer data, your company must report the crime to the police and cybersecurity authorities.
  • Data Breach: In many countries, a business must tell a government data office about a data breach.
  • Emergency: Your business needs to know who to call if a cyberattack affects public safety, like a power outage.

Context

This control is about being prepared. It’s not just about reacting to a bad event; it’s about having a clear process in place before one happens. By having a plan, your organisation can act quickly and correctly. This protects your reputation, avoids legal trouble, and helps authorities do their job.

Relevant ISO 27001 Controls

The following controls from the ISO/IEC 27001:2022 standard are related to contact with authorities:

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top