Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.21 Registration, assessment and handling of information security incidents

Control Overview

This control requires the organization to implement a formal mechanism for registering and triaging all security alerts, system anomalies, and user reports. Rather than treating every anomaly as a full-scale crisis, the organization must establish objective assessment criteria to differentiate between benign security events and actual security incidents. Once an incident is confirmed, it must be logged and managed according to documented workflows, ensuring that every phase from containment through resolution is ledgered and reported to senior management for strategic oversight.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs the systematic evaluation of telemetry across all enterprise and client networks.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, ensuring that data collection is seamlessly paired with executive-level decision routing.

At anDREa, we maintain an unbroken chain of custody for all security data. Telemetry is funneled into our central ticketing and tracking infrastructure. Our framework explicitly designates the Management Team as the body responsible for reviewing anomalies and declaring an official security incident. The dual deployment of our assessment and response protocols guarantees that all findings are accompanied by technical evidence, while strict non-deletion and archiving rules within our ticketing system preserve unalterable audit trails for downstream regulatory scrutiny.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.25 - Assessment and decision on information security eventsMandates that information security events are assessed and categorized using predefined criteria to determine if they constitute incidents.
ISO/IEC 27001A.05.26 - Response to information security incidentsControls the step-by-step operational resolution, communication routing, and final closure documentation for validated breaches.
Operational RegistryIssues and Risk LoggingThe permanent, unalterable ledger used to record anomalies, track investigation metadata, and archive evidence attachments.
Triage ManualHow to handle incident ticketsTechnical operational playbook defining the workflow paths, escalating triggers, and documentation standards for ongoing investigations.
Executive ReportsHow to handle incident ticketsDocumented decisions and meeting records proving active management involvement in the formal classification and declaration of incidents.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The triage workflows, evidence collection mandates, and management assessment loops are operationalized and traceably logged. Continuous Improvement: To align perfectly with European cyber regulations, ensure that your ticketing templates include explicit check boxes or data fields that map internal severity definitions directly to the official NIS 2 "significant incident" reporting thresholds.