N.2.07 Reporting of information security events
Control Overview
This control mandates that the organization establishes, communicates, and maintains clear, accessible channels for reporting perceived, suspected, or actual information security events and vulnerabilities. To minimize response latency and prevent minor anomalies from escalating into severe incidents, employees must be equipped with straightforward instructions on how to flag security concerns. The intake process must ensure that reports are routed immediately to a designated response point and logged systematically for formal triage.
Applicability Note: This control is fully applicable to the anDREa platform, governing incident and vulnerability reporting pathways for all staff, developers, and support teams.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, lowering the barrier to entry for internal reporting while enforcing structured technical routing behind the scenes.
anDREa provides multiple, redundant communication channels to ensure personnel can report anomalies instantly, regardless of the time or their operational context. Rather than restricting staff to a single complex interface, we support reporting via a dedicated security email address (security@andrea-cloud.com), direct phone lines, WhatsApp channels, and our internal ticketing infrastructure. All incoming alerts are bound directly to our Issues and Risk Logging system under our core event reporting protocols, ensuring that employee observations seamlessly trigger our structured security assessment and incident response workflows.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | Annex A.6.8 (Info. security event reporting) | Mandates that the organization provides a mechanism for personnel to report observed or suspected information security events through appropriate channels as quickly as possible. |
| User Instructions | Knowledge Base: "How to report (suspected) security incidents" | The primary internal reference article outlining approved reporting channels, contact details, and what details to include. |
| Dedicated Ingestion Nodes | security@andrea-cloud.com & Emergency Channels | The monitored, centralized communication points allocated specifically for security intake. |
| Operational Tracking | Issues and Risk Logging | The live engineering and management database where reported events are structured, historical tracking is preserved, and triage is initiated. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Redundant intake channels, clear documentation, and direct logging system integration are fully functional. Continuous Improvement: Implement periodic internal awareness campaigns specifically emphasizing the relevance of reporting under the NIS 2 directive to reinforce compliance visibility and maintain low reporting latency.