Castleforce IT Security Team

A.13 Information security incident management

A.13.1 Reporting information security events and weaknesses

Objective: To ensure information security events and weaknesses associated with information systems are communicated in a manner allowing timely corrective action to be taken.

A.13.1.1 Reporting information security events

Control

Information security events shall be reported through appropriate management channels as quickly as possible.

A.13.1.2 Reporting security weaknesses

Control

All employees, contractors and third party users of information systems and services shall be required to note and report any observed or suspected security weaknesses in systems or services.

Contact Castleforce for help with ISO27001