
Objective: To ensure information security events and weaknesses associated with information systems are communicated in a manner allowing timely corrective action to be taken.
Control
Information security events shall be reported through appropriate management channels as quickly as possible.
Control
All employees, contractors and third party users of information systems and services shall be required to note and report any observed or suspected security weaknesses in systems or services.
© Copyright Castleforce 2007-2012. Web design by Theme Group