Contact with Authorities

There are risks and costs to action. But they are far less than the long range risks of comfortable inaction.
— John F. Kennedy (applicable to proactive security measures)

ISO Control A.6.1.3: Guide for Engineers, Analysts, Managers, and Auditors

ISO Control A.6.1.3 mandates that organizations “Maintain appropriate contacts with relevant authorities.” This control underscores the importance of establishing and nurturing relationships with regulatory bodies, law enforcement agencies, and other relevant entities in the cybersecurity landscape.

By fostering these connections, organizations can ensure they have open channels of communication to facilitate timely reporting and response in the event of a security incident. This proactive approach can significantly minimize the impact of a breach, enabling swift action to contain the threat and mitigate potential damage.

Beyond incident response, maintaining contacts with relevant authorities plays a pivotal role in ensuring ongoing compliance with evolving regulations and standards. Regular interactions allow organizations to stay abreast of the latest legal requirements, ensuring their information security practices align with industry best practices. Additionally, these relationships provide a valuable source of threat intelligence, enabling organizations to stay informed about emerging threats and vulnerabilities, and proactively adapt their security measures to address these risks.

 

Why It Matters

Maintaining appropriate contacts with authorities is not just a checkbox exercise—it's a critical component of a robust security strategy. As Bruce Schneier, a renowned security expert, once said,

"Security is a process, not a product."

Part of this process involves collaboration with external entities, including relevant authorities. Proper implementation of this control can:

  1. Expedite incident response and resolution

  2. Ensure compliance with legal and regulatory requirements

  3. Provide access to valuable threat intelligence and best practices

  4. Facilitate smoother operations during crises or significant security events

 

For Engineers

Engineers play a crucial role in implementing the technical aspects of maintaining contact with authorities.

Responsibilities include:

  • Implement secure communication channels for contacting authorities

  • Ensure systems can generate the necessary data for authority reporting

  • Maintain the technical infrastructure to support information sharing

Key Actions:

  1. Develop and maintain secure data exchange protocols with relevant authorities

  2. Implement logging and reporting systems that align with authority requirements

  3. Ensure network configurations allow for secure communication with authority systems

  4. Regularly test and update communication systems used for authority contact

Best Practices:

  • Stay informed about technical standards and protocols used by relevant authorities

  • Participate in technical working groups or forums that involve authority representatives

  • Document all technical processes related to authority communication

 

For Analysts

Security analysts are often at the forefront of interpreting and acting on information shared with authorities.

Responsibilities:

  • Monitor and analyze security events that may require authority notification

  • Prepare detailed reports for submission to authorities

  • Interpret and apply threat intelligence received from authorities

Key Actions:

  1. Establish criteria for events that require authority notification

  2. Develop templates and procedures for authority reporting

  3. Analyze and disseminate threat intelligence received from authorities

  4. Maintain a database of relevant authority contacts and their areas of responsibility

Best Practices:

  • Regularly review and update notification criteria and reporting procedures

  • Participate in information sharing programs run by relevant authorities

  • Conduct periodic tabletop exercises simulating scenarios requiring authority contact

 

For Managers

Managers are responsible for overseeing the strategic aspects of authority contact and ensuring organizational compliance.

Responsibilities:

  • Establish and maintain relationships with key authority figures

  • Ensure the organization has clear policies for authority contact

  • Allocate resources for maintaining effective authority communication

Key Actions:

  1. Develop a comprehensive policy for authority contact, including roles and responsibilities

  2. Establish a team or designate individuals responsible for authority communication

  3. Ensure regular training on authority contact procedures for relevant staff

  4. Review and approve formal communications with authorities

Best Practices:

  • Attend industry events where authority representatives are present

  • Regularly review the effectiveness of authority contact procedures

  • Ensure authority contact is integrated into the overall incident response plan

 

For Auditors

Auditors play a crucial role in ensuring that the organization's practices for authority contact meet required standards.

Responsibilities:

  • Verify compliance with ISO Control A.6.1.3

  • Assess the effectiveness of authority contact procedures

  • Identify areas for improvement in authority communication

Key Actions:

  1. Review documentation of authority contacts and communication procedures

  2. Verify that appropriate staff are aware of and trained on authority contact procedures

  3. Check that secure communication channels for authority contact are in place and functional

  4. Assess the timeliness and appropriateness of past authority communications

Best Practices:

  • Stay informed about regulatory requirements related to authority contact

  • Conduct interviews with key personnel involved in authority communication

  • Review logs and records of past authority communications

 

General Best Practices

  1. Maintain an up-to-date contact list of relevant authorities

  2. Regularly review and update authority contact procedures

  3. Conduct annual tabletop exercises involving authority contact scenarios

  4. Ensure clear escalation procedures for authority communication

  5. Document all communications with authorities


Noteworthy Statistics and Events

  1. According to the Ponemon Institute's 2021 Cost of a Data Breach Report, involvement of regulatory authorities increased the average cost of a data breach by $340,000.

  2. The 2021 Verizon Data Breach Investigations Report found that 86% of breaches were financially motivated, highlighting the importance of maintaining contact with law enforcement authorities.

  3. In 2020, the SolarWinds supply chain attack affected multiple government agencies, emphasizing the need for strong public-private partnerships and communication channels with authorities.

  4. A 2022 survey by ISACA found that only 43% of organizations always notify relevant authorities of cybersecurity incidents that affect them.

  5. The Colonial Pipeline ransomware attack in 2021 demonstrated the critical role of authority contact, as the FBI's involvement was crucial in recovering a significant portion of the ransom payment.

 

Conclusion

As former FBI Director Robert Mueller once said,

"There are only two types of companies: those that have been hacked, and those that will be."

In this context, having established relationships and communication channels with relevant authorities can make a significant difference in how an organization weathers a security crisis.

By following the guidelines in this document and staying proactive in authority communications, organizations can enhance their security posture, ensure regulatory compliance, and be better prepared to handle security incidents when they occur.

Previous
Previous

Contact with Special Interest Groups

Next
Next

Segregation of Duties