N.1.21 Registration, assessment and handling of information security incidents
Control Overview
This control requires the organization to implement a formal mechanism for registering and triaging all security alerts, system anomalies, and user reports. Rather than treating every anomaly as a full-scale crisis, the organization must establish objective assessment criteria to differentiate between benign security events and actual security incidents. Once an incident is confirmed, it must be logged and managed according to documented workflows, ensuring that every phase from containment through resolution is ledgered and reported to senior management for strategic oversight.
Applicability Note: This control is fully applicable to the anDREa platform and governs the systematic evaluation of telemetry across all enterprise and client networks.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, ensuring that data collection is seamlessly paired with executive-level decision routing.
At anDREa, we maintain an unbroken chain of custody for all security data. Telemetry is funneled into our central ticketing and tracking infrastructure. Our framework explicitly designates the Management Team as the body responsible for reviewing anomalies and declaring an official security incident. The dual deployment of our assessment and response protocols guarantees that all findings are accompanied by technical evidence, while strict non-deletion and archiving rules within our ticketing system preserve unalterable audit trails for downstream regulatory scrutiny.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.25 - Assessment and decision on information security events | Mandates that information security events are assessed and categorized using predefined criteria to determine if they constitute incidents. |
| ISO/IEC 27001 | A.05.26 - Response to information security incidents | Controls the step-by-step operational resolution, communication routing, and final closure documentation for validated breaches. |
| Operational Registry | Issues and Risk Logging | The permanent, unalterable ledger used to record anomalies, track investigation metadata, and archive evidence attachments. |
| Triage Manual | How to handle incident tickets | Technical operational playbook defining the workflow paths, escalating triggers, and documentation standards for ongoing investigations. |
| Executive Reports | How to handle incident tickets | Documented decisions and meeting records proving active management involvement in the formal classification and declaration of incidents. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The triage workflows, evidence collection mandates, and management assessment loops are operationalized and traceably logged. Continuous Improvement: To align perfectly with European cyber regulations, ensure that your ticketing templates include explicit check boxes or data fields that map internal severity definitions directly to the official NIS 2 "significant incident" reporting thresholds.