ISO27001:2022 – A5.5

Contact with authorities

Introduction

One reason organisations implement ISO27001 is to comply with the requirements of a specific contract or legal or regulatory obligation. This is why ISO 27001 – A5.5 expects you to establish and maintain contact with relevant authorities.

In order to do this correctly, there are several steps you need to follow. But let’s look at the requirement first and go from there.

What does ISO 27001 – A5.5 require?

The standard states that:

“The organisation shall establish and maintain contact with relevant authorities.” (A5.5 Contact with Authorities)

To establish who the relevant authorities are, we need to identify them. This may require speaking with your organisation’s leaders, or it might be relatively obvious depending on the sector you operate in.

Why is this required?

If there is an incident such as a cyber-attack or data breach, you need to ensure someone has an established relationship with the relevant authorities and knows who to contact. In an emergency, this can be incredibly important as the authorities may offer support and guidance that is invaluable during an incident.

What the auditor is looking for

The auditor is looking for a list of relevant authorities that you may need to contact. This information may be contained within your business continuity plans or kept as a separate document. We prefer keeping it separate (as it’s easier to maintain) but referencing it in our Subject Access Request (SAR) process, Incident Management Plans, and Disaster Recovery Plans (refer to other ISO controls,, such as A5.25 – Information security incident management planning and preparation)

Ensure you also identify who is responsible for maintaining these contacts. For example, your Data Protection Officer (DPO) might be the point of contact with the Supervisory Authority. But who manages client communications?

To develop this Authorities Register, gather contact information for law enforcement, regulatory bodies, and supervisory authorities, based on your legal, regulatory, and contractual obligations. Speak to your business leaders to identify who governs your operations and capture this centrally.

Communication with Authorities

The auditor might also want to see evidence of when and how communication has taken place. If no communication has occurred yet, being able to explain the process may suffice. This is why we recommend referencing the register in your Business Continuity plans with a statement like:
“It is the responsibility of the relationship owner to speak to the relevant authority, listed within the ‘Authorities Register.’”

Q & A

Who are the ‘relevant’ authorities for my organisation?

This will vary depending on your business. A good starting point is the Supervisory Authority for your region. In the UK, this is the Information Commissioner’s Office (ICO). Your sector and contracts will determine others. Ask your business leaders who you are regulated by.

What do I have to share with the authority?

This depends on the authority and situation. For example, in the case of a data breach reported to the ICO, detailed information is required. Building these relationships ahead of time ensures you understand what’s expected when the time comes.

Is there a time limit on when I need to speak to authorities?

It depends. For data breaches affecting data subjects, you must report to the Supervisory Authority without undue delay — no more than 72 hours after discovering the breach. Other authorities may have different timelines. The key is to establish relationships and expectations before a breach occurs.

Difficulty rating

We rate this a 1 out of 5. No technical skills are needed, but it does require internal communication and compiling a central register of relevant authorities.

More questions?

ISO27001 controls do not exist in isolation. Review our FAQ for more context across the standard.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book “The Real Easy Guide to ISO27001”, available on Amazon.

ISO 27001 – A5.5