SID-PPL-04 — Information Security Event Reporting
| Property | Value |
|---|---|
| Status | to_do |
| Owner | operator |
| Category | process |
| CSF Function | detect |
| Group | People Security Controls |
Description
Personnel must report observed or suspected information security events through defined channels. No retaliation for good-faith reporting. Response within documented SLA.
Audit Findings
| Finding | Severity | Status |
|---|---|---|
| ISO-P-2 — Partial security event reporting | low | open |