ISO 27001 6.8 Information Security Event Reporting Requirement:
"The organization shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner."[1]
ISO 27001 6.8 Information Security Event Reporting Requirement Explanation:
An email address and phone number should be provided to all personnel for purposes of reporting actual or suspected information security incidents.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you