Provide a mechanism for personnel to report observed or suspected IS events through appropriate channels in a timely manner.
Also written as A6.8, Annex A 6.8, ISO 27001:2022 A.6.8, ISO27001 A.6.8.
Information security event reporting is one of 8 People Controls in ISO/IEC 27001:2022 Annex A. Provide a mechanism for personnel to report observed or suspected IS events through appropriate channels in a timely manner. People controls are tested against HR records, so the evidence usually lives outside the security team — joiner/mover/leaver files, training completions, and signed acknowledgements need to reconcile with your current headcount.
When preparing your Statement of Applicability (SoA) for A.6.8, gather artefacts such as:
If you run more than one framework, the same evidence usually satisfies all of them. A.6.8 aligns with:
SOC 2: CC2.2 Internal communication, CC2.3 External communication, CC7.3 Security event evaluation
NIST CSF 2.0: DE.AE-06 Event information provided to stakeholders, RS.MA-02 Incident report triage and validation
A.6.8 consolidates the following ISO 27001:2013 control(s): A.16.1.2, A.16.1.3. If you are transitioning an existing ISMS, map your prior evidence for these to A.6.8 in your updated SoA.
Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.6.8 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.
In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.
ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.
A.6.8 aligns with SOC 2 CC2.2, CC2.3, CC7.3 and NIST CSF DE.AE-06, RS.MA-02. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.
A.6.8 consolidates 2 control(s) from the 2013 edition: A.16.1.2, A.16.1.3. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.