OIS-05 Contact with Relevant Government Agencies and Interest Groups
Maintain working contact with relevant authorities and security interest groups to obtain current threat and vulnerability intelligence, and feed what is received into the risk handling and vulnerability handling procedu
4
artefacts
1
held by a system
0
at each review
moderate
to go live
Ticketing / ITSM
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Advisories received during the period traced to the tickets or register entries they triggered · Ticketing / ITSM
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Membership confirmations or subscriptions for security interest groups and advisory feeds · Document repository
- Register of named authority contacts showing the date of the last exchange with each · Policy repository / GRC workspace
- Notes from information exchange meetings or briefings attended by provider staff · Document repository
First move
Start with the 1 of 4 artefacts that already live in a system (Ticketing / ITSM); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Feeds subscribed to but nothing shows anyone reads or acts on them
- Received advisories cannot be traced to any vulnerability handling or risk decision
- Named contacts have left the organisation and were never replaced
- German public sector customers are served with no BSI channel established at all
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetOIS-04 Segregation of Duties · OIS-06 Risk Management Policy