A.5.5 Contact with authorities
1. Objective and Communication Governance
anDREa establishes, maintains, and structurally manages open channels of communication with relevant external administrative, regulatory, and legal authorities. This proactive outreach satisfies ISO/IEC 27001 Annex A.5.5 and ensures compliant reporting speeds during technical crises or data security anomalies.
All official communication, formal disclosure submissions, and emergency alerts directed to authoritative external bodies are executed exclusively by the Director or delegated members of the Management Team. This central oversight guarantees that all delivered information is legally accurate, properly curated, and synchronized with our contractual commitments.
2. Monitored Jurisdictional & Regulatory Authorities
Our operational contact matrix bridges standard corporate compliance with specialized public safety bodies, including but not limited to:
- Cybersecurity Defense Infrastructure: The Nationaal Cyber Security Centrum (NCSC-NL) is our primary contact point for threat landscape changes, zero-day threat profiles, and statutory security incident escalation (NCSC Contact Hub).
- Data Protection & Privacy Supervision: The Autoriteit Persoonsgegevens (AP) serve*s as the direct supervisory authority for registering data leaks or notifying severe privacy non-conformities under GDPR requirements (see: Data Breach Procedure).
- Law Enforcement Networks: State and international law enforcement agencies are engaged directly following validated cyber-forensic incidents involving malicious intent, illegal system access, data theft, or corporate extortion.
- Government Authorities: Relevant national and sector-specific governmental bodies are contacted when required by legislative evolutions or compliance shifts within health-data hosting frameworks.
3. Institutional Contact Registry
To ensure rapid, error-free communication during a crisis, anDREa maintains an updated Security & Privacy Contacts within its secure Google Workspace files. This directory is reviewed during standard ISMB cycles and contains the following parameters for each entity:
┌────────────────────────────────────────────────────────┐ │ Authority Contact Directory │ ├────────────────────────────────────────────────────────┤ │ • Official Institutional Name │ │ • Defined Purpose of Contact (e.g., NIS 2 / Breach) │ │ • Emergency Points of Contact (Hotlines, Portals, API) │ │ • Internal Assigned Owner (Director / Management Team) │ └────────────────────────────────────────────────────────┘
4. Governance Registries and Audit Evidence
To demonstrate active maintenance of these communication channels to external certification bodies, the following internal directories serve as evidence:
- Authority Contact Directory: The master registry mapping out addresses, portals, and emergency hotlines for supervisory entities (see: Security & Privacy Contacts).
- Issues and Risk Logging Framework: Archival logs containing historical records of notifications sent to outside regulators, ensuring an auditable verification trail (see: Issues and Risk Logging).