A.5.5 Organizational
Contact with authorities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (8)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- IR-6mostlyaligns with — Both controls require the organization to define when, how, and by whom security incidents are reported to external authorities such as regulators or law enforcement.
- IR-4partialaligns with — The ISO control supports the incident-handling process by specifying the external-reporting component that NIST treats as one element of coordinated incident response.
- IR-8partialaligns with — Establishing contact procedures with authorities is a required element of the incident-response plan that the ISO control directly addresses.
- SI-5partialaligns with — Both controls use ongoing interaction with authorities to obtain and act on security alerts, advisories, and regulatory expectations.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.CO-02mostlyaligns with — The ISO control's requirement to define when and by whom authorities are contacted during incidents directly supports the CSF outcome of notifying internal and external stakeholders of incidents.
- RS.CO-03mostlyaligns with — Specifying how and when security incidents are reported to authorities fulfills the CSF outcome of sharing information with designated internal and external stakeholders.
- GV.OC-03partialaligns with — Using contacts with authorities to understand regulatory expectations helps ensure the organization meets legal, regulatory, and contractual cybersecurity requirements.
- GV.SC-08partialaligns with — Including relevant authorities in incident planning and response activities aligns with the CSF outcome of incorporating third parties into incident response processes.
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (2)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialfinds — Requiring contact with supervisory authorities when breaches occur compels organizations to identify and contain unauthorized disclosures of sensitive information rather than allowing them to persist undetected.
- CWE-778nonenone — Mandating timely external reporting of security incidents forces organizations to maintain evidence trails and detection processes that would otherwise allow incidents to remain hidden or unaddressed.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09partialfinds — Mandating timely, authorized reporting of incidents to regulators and law enforcement ensures that security events are escalated beyond internal teams, reducing the chance that critical alerts are missed or mishandled.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.