What are regulatory and law enforcement contacts?
Regulatory and law enforcement contacts are the authorities an organization may need to notify or involve during a security incident. Examples include data protection supervisory authorities under GDPR and national cybercrime units. Frameworks such as the CSA CCM expect these contacts to be documented in advance.
What the buyer is really asking
If you have to report a breach to a regulator or call law enforcement, do you know who to contact? Say where those contacts are kept, usually in the incident response plan, and who owns them.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you maintain points of contact for regulatory authorities?”
- “Who would you notify at law enforcement during an incident?”
- “Do you know which supervisory authority you report to?”
Evidence to have ready
- The contacts appendix of your incident response plan
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.