Whistlelink webinar: Ustawa o ochronie sygnalistów – nowe obowiązki pracodawców Zarejestruj się

Secure whistleblowing to support your ISO/IEC 27001 ISMS

Annex A control 6.8 asks that personnel can report observed and suspected information security events through appropriate channels, in good time. Whistlelink gives them one they will use.

Why organisations choose Whistlelink

We run the standard ourselves. Whistlelink Solutions AB is certified to ISO/IEC 27001, with all data hosted in the EU.

Where ISO/IEC 27001 and internal reporting meet

Annex A 6.8, Information security event reporting, asks that personnel can report suspected security events promptly, through appropriate channels. It does not require the channel to be anonymous — a form or a mailbox satisfies it.

What a mailbox does not solve is the event involving a manager, a colleague or a supplier, where the person who noticed weighs up what reporting will cost them. Those are the events that stay unreported longest.

An anonymous, structured channel exceeds the baseline of 6.8 and ties it to the controls around it — awareness training, the disciplinary process and management responsibilities.

For compliance, risk and security teams

Certification turns on evidence. A control that exists on paper but has no records behind it is the one the auditor asks about.

For HR and people teams

Control 6.8 sits in the middle of the people controls, not the technical ones.

For leaders and management

An ISMS is judged on whether it improves. The events nobody reports are the ones your management review never sees.

ISO 27001 and NIS2

ENISA’s technical implementation guidance maps the NIS2 cybersecurity risk-management requirements to ISO/IEC 27001:2022 and 27002:2022, so an existing ISMS gives you a substantial head start. ENISA is explicit that the mapping is not a measure of equivalence: certification supports your case, it does not by itself demonstrate NIS2 compliance.

NIS2 and secure internal reporting →

Let's talk!

Want to give your people a reporting route they will actually use, and evidence Annex A 6.8 when the auditor asks?

Let’s explore how Whistlelink can support your ISMS and strengthen the way information security events are reported and resolved.

whistlelink-logo-white-2022.svg

Porozmawiaj z działem sprzedaży

Czy potrzebujesz pomocy w wyborze odpowiedniego planu dla Twojej organizacji lub chciałbyś dowiedzieć się, jak w pełni wykorzystać potencjał systemu Whistlelink?

→ Or go to our page with Frequently Asked Questions

Uzyskaj wsparcie produktowe

Potrzebujesz szybkiej pomocy związanej z naszym produktem lub napotkałeś jakieś problemy? Jesteśmy tutaj, aby Tobie pomóc.

Uwaga! Prosimy upewnić się, że nie dołączasz żadnych informacji ani danych osobowych dotyczących konkretnych przypadków zgłaszania nieprawidłowości. W przypadku umieszczenia takich informacji, zgłoszenie zostanie natychmiast usunięte.

Skontaktuj się z nami

Z PRZYJEMNOŚCIĄ SPOTKAMY SIĘ Z TOBĄ

Skontaktuj się​

Nasz zespół jest gotowy, aby odpowiedzieć na Twoje pytania.

Territory Manager
Urszula Garbicz-Bryś

Skontaktuj się

Wypełnij poniższy formularz, a my skontaktujemy się z Tobą możliwie najszybciej.

Porozmawiaj z Territory Managerem Urszula Bryś

HAPPY TO MEET YOU!

Get in touch

Our team is ready to answer your questions. Find the answer by visiting our support centre, or fill out the form below and we'll be in touch as soon as possible. Or simply give us a call!

Talk with Territory Manager
Annelie Demred

annelie.demred@whistlelink.com

Annelie Demred, CEO Whistlelink.