A.5.5 Organizational
Contact with authorities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- IR-6mostlyaligns with — Both controls require the organization to define when, how, and by whom security incidents are reported to external authorities such as regulators or law enforcement.
- IR-4partialaligns with — The ISO control supports the incident-handling process by specifying the external-reporting component that NIST treats as one element of coordinated incident response.
- IR-8partialaligns with — Establishing contact procedures with authorities is a required element of the incident-response plan that the ISO control directly addresses.
- SI-5partialaligns with — Both controls use ongoing interaction with authorities to obtain and act on security alerts, advisories, and regulatory expectations.
- IR-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (13)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.CO-02mostlyaligns with — The ISO control's requirement to define when and by whom authorities are contacted during incidents directly supports the CSF outcome of notifying internal and external stakeholders of incidents.
- RS.CO-03mostlyaligns with — Specifying how and when security incidents are reported to authorities fulfills the CSF outcome of sharing information with designated internal and external stakeholders.
- GV.OC-03partialaligns with — Using contacts with authorities to understand regulatory expectations helps ensure the organization meets legal, regulatory, and contractual cybersecurity requirements.
- GV.SC-08partialaligns with — Including relevant authorities in incident planning and response activities aligns with the CSF outcome of incorporating third parties into incident response processes.
- GV.OC-03implements — A.5.5 operationalizes the flow of information with legal/regulatory/supervisory authorities that is required to understand and manage those exact cybersecurity requirements in GV.OC-03; the link is by subject membership in the governance domain rather than explicit citation of the control.
- GV.SC-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.CO-03implements — A.5.5 operationalizes the sharing of security-related information with external authorities (a core subset of the designated external stakeholders named in RS.CO-03)
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (1)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200finds — Requiring contact with supervisory authorities when breaches occur compels organizations to identify and contain unauthorized disclosures of sensitive information rather than allowing them to persist undetected.
Mitigated MITRE ATT&CK techniques (67)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1486responds — A.5.5 requires timely reporting of identified incidents to authorities and uses those contacts to understand expectations, which directly matches the incident-response act of containment/eradication once ransomware (T1486) is underway; the named remainder is that reporting itself does not perform the on-system containment or eradication steps.
- T1531responds — A.5.5 requires timely reporting of identified incidents to authorities and uses those contacts to understand expectations, which directly supports the incident response process that contains/eradicates an ongoing T1531 ransomware-style account lockout before full impact (e.g. subsequent encryption).
- T1657responds — A.5.5 requires timely reporting of identified incidents to authorities and designates who contacts them, which directly engages the core of `responds` (containment/eradication/follow-up once financial theft is underway) for the ransomware/BEC/extortion shapes that dominate T1657; the remainder is pre-compromise social engineering or pure technical theft where no organizational incident has yet materialized to respond to.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.