INC-010 External Contact and Communication Points
Description
Up-to-date contact information is maintained for relevant regulatory authorities, law enforcement, national CERTs, cloud providers, and legal counsel. These contacts are accessible to the incident response team during an active incident. Contact lists are reviewed and verified at least annually.
Rationale
During an active incident, searching for regulator contact details wastes critical time. Pre-established, verified contact lists are an operational readiness requirement.
Applicability (9 profiles)
The contact list gains entries the base does not produce: the market surveillance authority of each Member State the system is made available in, because Art.20 informs them where the system presents a risk within the meaning of Art.79(1) and Art.73 reports serious incidents to the ones where the incident occurred. The notified body involved in the conformity assessment, which Art.73 brings into the investigation and which Art.22 requires an authorised representative to inform on terminating its mandate. The distributors, deployers, importers and authorised representative Art.20 names belong on the same list, because the corrective action message reaches them on the same trigger.
The contact list acquires named entries: the CSIRT and the competent authority of the Member State in which the provider is regarded as established, and the CSIRT designated as coordinator for coordinated vulnerability disclosure under Art. 12(1). Annex point 4.3.2(b) requires the communication means to carry non-obligatory communications too, so the list is a working channel rather than an emergency one.
Framework Mappings (10)
| SEF-10 | Points of Contact Maintenance | full |
| SEF-10 | Points of Contact Maintenance | full |
| EU-AI-Art.20 | Provider Obligations — Corrective Actions and Duty of Information | informative |
| EU-AI-Art.21 | Provider Obligations — Cooperation with Competent Authorities | informative |
| EU-AI-Art.5.4 | Prohibited Practices — Notification of Each Real-Time Remote Biometric Identification Use | informative |
| 5.5 | Contact with authorities | full |
| NIS2-Art.23.1 | Notification of Significant Incidents | informative |
| NIS2-CIR-4.3 | Crisis Management | informative |
| IR-6 | Incident Reporting | partial |
| IR-7 | Incident Response Assistance | partial |
Evidence (2)
Verified external contact list maintained by the incident response team, covering regulatory authorities, law enforcement, national CERTs, cloud providers, and legal counsel.
Example: IR External Contact Register (version-controlled, reviewed within the last 12 months) listing organisation name, contact name, phone, email, and relationship (e.g., supervisory authority, CERT-EU, AWS security contact, external legal counsel)
Test: Request the external contact list and the most recent verification record. Verify: (1) contacts cover at minimum: relevant DPA/supervisory authority, national CERT, primary cloud provider security contact, and external legal counsel; (2) contact details were verified (e.g., a test call or email confirmation) within the last 12 months; (3) the list is accessible to the IR team during an incident without requiring access to primary systems; (4) the last verification date is documented.
Procedure for maintaining and verifying external contacts, defining the review frequency, verification method, and responsible owner.
Example: IRP section or standalone External Contact Maintenance Procedure (version-controlled) specifying which contact categories must be maintained, the annual verification process, and who is responsible for keeping the list current
Test: Request the external contact maintenance procedure. Verify: (1) the procedure defines which contact categories are required; (2) a verification method and frequency are specified (at least annual); (3) a named role is responsible for maintaining and verifying the list; (4) the procedure is referenced in the IRP.
Questions (2)
Is a contact list maintained for the external parties the incident response team may need to reach?
The contact list must be accessible without requiring access to primary production systems: it should be stored out-of-band (e.g. printed copy, offline document, or separate communications platform).
Which external contact categories are included in your maintained IR contact list?
Supervisory authority, national CERT, cloud provider security contact, and legal counsel are the minimum required categories. Insurance and DFIR retainer contacts are expected for mature IR programmes.