Skip to content
arrow_back
search
Annex A 5.5 verified ISO/IEC 27001:2022

Establish and Maintain Contact with Authorities

Ensure you can quickly contact authorities like police or regulators for security issues.

record_voice_over

Plain language

This control is about making sure your organisation can quickly get in touch with the right authorities, like the police or regulators, when a security issue happens. This is important because delays in contacting authorities can make security problems worse and harder to fix.

Framework

ISO/IEC 27001:2022

Control effect

Proactive

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The organization shall establish and maintain contact with relevant authorities.
verified ISO/IEC 27001:2022 Annex A 5.5
priority_high

Why it matters

Delayed or absent contact with authorities can escalate incidents, causing reputational damage and regulatory or legal consequences.

settings

Operational notes

Regularly test and update authority contact details, after-hours numbers, and liaison roles so escalation to relevant regulators or police works in an emergency.

Mapping detail

Mapping

Direction

Controls