A.6.8 Information Security Event Reporting
Control Objective
The organisation shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.
Policy Statement
anDREa maintains multiple accessible reporting channels to ensure that observed or suspected security events are captured, escalated, and addressed without delay. Mandatory, annual training ensures all personnel understand how to identify and report events, supporting our strict commitment to the 24-hour statutory notification timelines mandated by NIS 2 and GDPR.
Incident Reporting Channels
Personnel and interested parties can report any potential security anomaly, threat, or policy violation through the following official channels:
- Internal Ticketing: Submit an incident ticket directly within the Security-Related Incidents Department queue.
- Dedicated Email: Send an explicit alert to
security@andrea-cloud.com(monitored by Quality & Assurance and the Management Team). - Rapid Chat Escalation: Alert the response team via the dedicated, internal SECURITY Google Chat Group.
- Direct Liaison: Contact a member of the Management Team directly.
Regardless of the initial intake channel utilized, all confirmed or highly suspected events must be formally registered in the centralized ticketing system to preserve an auditable trail.
Critical Escalation & NIS 2 Compliance
To guarantee alignment with regional regulatory frameworks, anDREa enforces a strict emergency reporting tier based on operational impact:
- Urgency Trigger: Any event causing or threatening severe operational disruption, platform downtime, or financial impact must be reported immediately.
- Immediate Actions: Personnel must instantly use the Emergency Escalation Form or submit an incident with "P1" (Priority 1) Ticket Status.
- Statutory Compliance: This rapid escalation pathway ensures that the Management Team can evaluate the event and meet the mandatory 24-hour initial reporting deadline to government Computer Security Incident Response Teams (CSIRTs) and regulatory bodies under NIS 2 and GDPR guidelines.
Administration & Cross-References
- External Threat Intelligence: Security researchers and external entities should report discovered flaws via our public-facing Coordinated Vulnerability Discosure Policy.
- Downstream Mitigation: Technical containment, eradication, and post-incident investigation steps are governed under A.05.26: Response to Information Security Incidents.
- Escalation Hub: Immediate external reporting metrics and quick links can be found at Security & Privacy Contacts.