ISO/IEC 27001:2022 Annex A · Control 6.8
Information Security Event Reporting: A Practical Implementation Guide
Make it easy and safe for people to report suspected security events quickly.
This control concerns providing mechanisms for personnel to report observed or suspected information security events through appropriate channels.
What should the control achieve?
- Personnel know what and how to report.
- Multiple accessible channels support urgent cases.
- Reports reach trained triage staff.
- Reporters receive guidance and appropriate feedback.
Step-by-step implementation
Define reportable examples
Include phishing, lost devices, misdirected data, suspicious behavior, control failures and supplier issues.
Create simple channels
Use a memorable email, button, hotline or service portal with urgent escalation.
Promote a positive culture
Emphasize rapid reporting and avoid punishing good-faith mistakes.
Capture essential facts
Ask what happened, when, affected assets and immediate safety without burdening the reporter.
Connect to triage
Ensure coverage, acknowledgements, severity assessment and escalation.
Test and improve
Use simulations, awareness checks and reporter feedback.
What this could look like in practice
Employees use a ‘Report suspicious email’ button that submits message details to Security. Lost devices use a 24/7 hotline. Reporters receive immediate instructions and later confirmation that the report was reviewed.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Phishing | One-click report preserves technical details. | Security ticket |
| Lost device | Hotline triggers session revocation and incident triage. | Call and incident log |
| Misdirected email | Reporter receives recall and containment guidance. | Event record |
| Supplier concern | Service owner routes report to Security. | Supplier event ticket |
Implementation evidence
- Event-reporting procedure
- Published channels
- Awareness materials
- Report records
- Acknowledgements
- Triage linkage
- Simulation results
- Feedback and improvements
Useful metrics
- Time from observation to report
- Employee reporting rate in simulations
- Reports acknowledged within target
- Events discovered externally before internal report
Common mistakes
- Using a channel unavailable during outages.
- Requiring long forms for urgent reports.
- Blaming people who report mistakes.
- Giving no feedback to reporters.
- Promoting phishing only while ignoring other events.
Questions an auditor may ask
- What events should personnel report?
- Which channels are available outside office hours?
- How quickly are reports acknowledged?
- How do simulations improve the process?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.