GASP: AICF

Search controls

Search by control ID, name or domain

GOV-017 Contact with Authorities and Special Interest Groups

Tier 2+

Description

The organization maintains documented contacts with relevant regulatory authorities, law enforcement, and security industry groups. These contacts are used to stay informed of emerging threats, regulatory changes, and sector guidance.

Rationale

Regulatory relationships and threat intelligence communities are early warning channels. Without maintained contacts, the organization learns about emerging risks and regulatory changes too late to respond proactively.

Framework Mappings (4)

GRC-08Special Interest Groupsfull
5.5Contact with authoritiesfull
5.6Contact with special interest groupsfull
PM-15Security and Privacy Groups and Associationspartial

Evidence (2)

recordmanual

Contacts register listing relationships with regulatory authorities, law enforcement, and security industry groups, with named internal contact and last-contact or subscription-verification date.

Example: Regulatory and industry contacts register (Confluence / spreadsheet) listing: contact name and organization (e.g. ICO, CERT/CC, CISA, relevant ISAC), type of relationship, named internal owner, and last-reviewed date.

Test: Request the contacts register. Verify: (1) relevant regulatory authorities for the organization's jurisdictions are listed, (2) at least one security industry group or threat intelligence source is listed, (3) each entry has an internal owner, (4) the register has been reviewed within the last 12 months.

recordmanual

Evidence of active participation in or subscription to a security community or information sharing group.

Example: ISAC membership confirmation email, FS-ISAC or H-ISAC membership certificate, CISA alert subscription confirmation, or equivalent — dated within the last 12 months.

Test: Request membership or subscription confirmation for at least one threat intelligence sharing or industry group. Verify: (1) the subscription or membership is current (not expired), (2) it is relevant to the organization's industry and technology stack, (3) a named internal contact is responsible for receiving and acting on alerts.

Questions (2)

boolean

Does your organization maintain documented contacts with relevant regulatory authorities, law enforcement, and security industry groups?

A contacts register should list each relationship, the named internal owner, and a last-reviewed date — covering both regulatory authorities for operating jurisdictions and at least one threat intelligence sharing group.

multi

Which of the following types of external security relationships does your organization actively maintain?

Regulatory authority contacts (e.g. data protection authority, financial regulator)Law enforcement point of contact for cyber incident reportingISAC or sector-specific threat sharing group membershipCISA / national CERT alert subscriptionVendor or MSSP threat intelligence feedNone of the above

Active membership or subscription (not just registration) is the expected standard — confirm the subscription or membership is current and has a named internal owner.