GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INC-010 External Contact and Communication Points

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Up-to-date contact information is maintained for relevant regulatory authorities, law enforcement, national CERTs, cloud providers, and legal counsel. These contacts are accessible to the incident response team during an active incident. Contact lists are reviewed and verified at least annually.

Rationale

During an active incident, searching for regulator contact details wastes critical time. Pre-established, verified contact lists are an operational readiness requirement.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

The contact list gains entries the base does not produce: the market surveillance authority of each Member State the system is made available in, because Art.20 informs them where the system presents a risk within the meaning of Art.79(1) and Art.73 reports serious incidents to the ones where the incident occurred. The notified body involved in the conformity assessment, which Art.73 brings into the investigation and which Art.22 requires an authorised representative to inform on terminating its mandate. The distributors, deployers, importers and authorised representative Art.20 names belong on the same list, because the corrective action message reaches them on the same trigger.

Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

The contact list acquires named entries: the CSIRT and the competent authority of the Member State in which the provider is regarded as established, and the CSIRT designated as coordinator for coordinated vulnerability disclosure under Art. 12(1). Annex point 4.3.2(b) requires the communication means to carry non-obligatory communications too, so the list is a working channel rather than an emergency one.

Framework Mappings (10)

SEF-10Points of Contact Maintenancefull
SEF-10Points of Contact Maintenancefull
EU-AI-Art.20Provider Obligations — Corrective Actions and Duty of Informationinformative
EU-AI-Art.21Provider Obligations — Cooperation with Competent Authoritiesinformative
EU-AI-Art.5.4Prohibited Practices — Notification of Each Real-Time Remote Biometric Identification Useinformative
5.5Contact with authoritiesfull
NIS2-Art.23.1Notification of Significant Incidentsinformative
NIS2-CIR-4.3Crisis Managementinformative
IR-6Incident Reportingpartial
IR-7Incident Response Assistancepartial

Evidence (2)

recorddocumentmanual

Verified external contact list maintained by the incident response team, covering regulatory authorities, law enforcement, national CERTs, cloud providers, and legal counsel.

Example: IR External Contact Register (version-controlled, reviewed within the last 12 months) listing organisation name, contact name, phone, email, and relationship (e.g., supervisory authority, CERT-EU, AWS security contact, external legal counsel)

Test: Request the external contact list and the most recent verification record. Verify: (1) contacts cover at minimum: relevant DPA/supervisory authority, national CERT, primary cloud provider security contact, and external legal counsel; (2) contact details were verified (e.g., a test call or email confirmation) within the last 12 months; (3) the list is accessible to the IR team during an incident without requiring access to primary systems; (4) the last verification date is documented.

policydocumentmanual

Procedure for maintaining and verifying external contacts, defining the review frequency, verification method, and responsible owner.

Example: IRP section or standalone External Contact Maintenance Procedure (version-controlled) specifying which contact categories must be maintained, the annual verification process, and who is responsible for keeping the list current

Test: Request the external contact maintenance procedure. Verify: (1) the procedure defines which contact categories are required; (2) a verification method and frequency are specified (at least annual); (3) a named role is responsible for maintaining and verifying the list; (4) the procedure is referenced in the IRP.

Questions (2)

boolean

Is a contact list maintained for the external parties the incident response team may need to reach?

The contact list must be accessible without requiring access to primary production systems: it should be stored out-of-band (e.g. printed copy, offline document, or separate communications platform).

multi

Which external contact categories are included in your maintained IR contact list?

Relevant data protection supervisory authority (e.g. ICO, CNIL)National or sector CERT (e.g. CERT-EU, NCSC)Primary cloud provider security contactExternal legal counsel with cyber incident experienceLaw enforcement contact (e.g. national cybercrime unit)Cyber insurance provider incident response hotlineExternal incident response retainer (e.g. DFIR firm)The list is verified within the last 12 monthsThe list is reachable without access to primary production systemsNone of the above

Supervisory authority, national CERT, cloud provider security contact, and legal counsel are the minimum required categories. Insurance and DFIR retainer contacts are expected for mature IR programmes.