Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.2.07 Reporting of information security events

Control Overview

This control mandates that the organization establishes, communicates, and maintains clear, accessible channels for reporting perceived, suspected, or actual information security events and vulnerabilities. To minimize response latency and prevent minor anomalies from escalating into severe incidents, employees must be equipped with straightforward instructions on how to flag security concerns. The intake process must ensure that reports are routed immediately to a designated response point and logged systematically for formal triage.

note

Applicability Note: This control is fully applicable to the anDREa platform, governing incident and vulnerability reporting pathways for all staff, developers, and support teams.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, lowering the barrier to entry for internal reporting while enforcing structured technical routing behind the scenes.

anDREa provides multiple, redundant communication channels to ensure personnel can report anomalies instantly, regardless of the time or their operational context. Rather than restricting staff to a single complex interface, we support reporting via a dedicated security email address (security@andrea-cloud.com), direct phone lines, WhatsApp channels, and our internal ticketing infrastructure. All incoming alerts are bound directly to our Issues and Risk Logging system under our core event reporting protocols, ensuring that employee observations seamlessly trigger our structured security assessment and incident response workflows.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001Annex A.6.8 (Info. security event reporting)Mandates that the organization provides a mechanism for personnel to report observed or suspected information security events through appropriate channels as quickly as possible.
User InstructionsKnowledge Base: "How to report (suspected) security incidents" The primary internal reference article outlining approved reporting channels, contact details, and what details to include.
Dedicated Ingestion Nodessecurity@andrea-cloud.com & Emergency ChannelsThe monitored, centralized communication points allocated specifically for security intake.
Operational TrackingIssues and Risk LoggingThe live engineering and management database where reported events are structured, historical tracking is preserved, and triage is initiated.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Redundant intake channels, clear documentation, and direct logging system integration are fully functional. Continuous Improvement: Implement periodic internal awareness campaigns specifically emphasizing the relevance of reporting under the NIS 2 directive to reinforce compliance visibility and maintain low reporting latency.