ISO 27001 control 6.8 requires a timely, appropriate channel through which personnel can report observed or suspected information security events, and a Microsoft Forms security event report form setup can provide that intake channel when it is restricted to your organization, monitored, and connected to a defined triage process. For a SaaS founder answering an enterprise security questionnaire, Microsoft Forms is a practical Microsoft 365 option for collecting consistent reports, identifying the reporter when appropriate, and retaining evidence that the reporting mechanism exists.
What does ISO 27001 control 6.8 require from an event-reporting channel?
ISO 27001:2022 control 6.8, Information Security Event Reporting, does not require a dedicated security operations platform. It requires your organization to provide personnel with an appropriate mechanism to report suspected or observed information security events promptly. A Microsoft Forms report form can satisfy the mechanism portion of the control if employees and contractors can find it, submit it without unnecessary barriers, and your organization has people responsible for reviewing and escalating submissions.
The form should collect enough information for initial triage without asking the reporter to determine whether an incident has occurred. Use language such as “observed or suspected” throughout. This matters for a small SaaS company: a customer-facing employee who receives a suspicious support request should be able to report it even if they do not know whether it is phishing, social engineering, or a legitimate request.
How do you complete a Microsoft Forms security event report form setup?
-
Sign in to
https://forms.office.comusing the Microsoft 365 account that will own the reporting process. Use a role-based or shared operational account only if your Microsoft 365 governance permits it; otherwise, create the form under the person accountable for security operations and document the ownership. -
Select New Form. Enter the form title
Information Security Event Report. In the description, add a concise reporting instruction, such as:Use this form to report any observed or suspected security event immediately. Examples include suspicious emails, lost devices, unauthorized access, exposed credentials, unusual system behavior, or accidental disclosure of company or customer data. For urgent active threats, also contact the security on-call channel immediately.
-
Select Add new and create the following questions. Turn on the Required toggle for the first five questions so every report contains minimum triage information.
Question type Question text Recommended setting Choice What type of event are you reporting? Required; choices: Suspicious email or message, Lost or stolen device, Suspected unauthorized access, Exposed password or secret, Data disclosure, Malware or unusual device behavior, Other Text What happened? Required; enable Long answer Date When did you first observe the event? Required Text Which system, customer account, device, or service may be affected? Required; enable Long answer Choice Is the event still active or likely to cause immediate harm? Required; choices: Yes, No, Unsure Text What actions have you already taken? Optional; enable Long answer Text Additional details, URLs, email subjects, or relevant identifiers Optional; enable Long answer -
For the first Choice question, select More settings for question and choose Add branching if you want to gather targeted details. For example, route the “Suspicious email or message” selection to a question asking for the sender address and email subject. Route “Lost or stolen device” to a question asking for the device name, last known location, and whether the device was locked. Keep branching simple; a reporting form should reduce delay rather than become an investigation worksheet.
-
Select the ... menu in the upper-right corner, then select Settings. Under Who can fill out this form, select Only people in my organization can respond. This prevents public internet submissions and allows Microsoft Forms to identify the signed-in reporter.
-
In the same Settings panel, enable Record name. Leave One response per person disabled unless your reporting policy specifically requires it; personnel may need to submit multiple unrelated reports. Confirm that Accept responses is enabled, and do not configure an end date for a standing security reporting channel.
-
Under Notifications in the form’s Settings panel, enable Get email notification of each response. Send these notifications to the person who is actually accountable for triage, such as the founder acting as security owner, a security lead, or a monitored shared mailbox. Do not rely on a mailbox that is only checked during business hours if your policy promises faster handling.
-
Select ..., then Settings, and customize the Thank you message. State what the reporter should expect and provide an urgent escalation route. For example:
Your report has been submitted to the security team for review. If this is an active compromise, lost device, exposed credential, or immediate customer-impacting issue, contact the security on-call channel or your designated emergency contact now.
-
Select Collect responses in the upper-right corner. Copy the internal response link. Publish that link in the places your personnel already use: your employee handbook, security policy, onboarding checklist, Microsoft Teams security channel, and internal knowledge base. A form that exists but cannot be located quickly is weak evidence of timely reporting.
How should a SaaS founder configure access and ownership safely?
For most early-stage SaaS organizations, choose Only people in my organization can respond and Record name. This creates an accountable internal channel and reduces anonymous spam. It also gives the reviewer the reporter’s Microsoft 365 identity, which is useful when an enterprise assessor asks how reports are investigated and how follow-up questions are handled.
Do not use Anyone can respond for your internal ISO 27001 reporting form unless you have a documented reason, compensating controls, and a separate plan to manage spam or malicious submissions. If contractors need access, provision them as guest users in Microsoft Entra ID only where your tenant configuration and Forms sharing settings support the intended access model. Test that arrangement before claiming it as part of your control.
Microsoft Forms does not provide strong operational resilience when a form belongs solely to an employee who leaves. Document the form owner in your control register and include a transfer or replacement step in offboarding. Where available in your Microsoft 365 environment, use a Microsoft 365 Group-owned form so responsibility is not tied to one founder’s account.
How do you verify that the Microsoft Forms configuration took effect?
-
Open the response link in a private browser session while signed in with a standard employee test account. Confirm that the form loads only after the employee signs in to your Microsoft 365 tenant.
-
Submit a test report using an identifiable, non-sensitive scenario such as
Test report: suspicious link received in internal chat. Do not place real credentials, customer data, or malware samples in the test submission. -
Return to the form owner’s Microsoft Forms page, open the form, and select the Responses tab. Confirm that the response count increased and that the response contains the test account’s name and timestamp.
-
Select Review answers and verify that required questions cannot be skipped, branching displays the intended follow-up question, and long-answer fields preserve the submitted text.
-
Confirm that the designated triage mailbox received the Microsoft Forms response notification. Record the time between submission and notification as evidence that the channel supports timely reporting.
-
Select Open in Excel from the Responses tab. Confirm that the export includes response timestamps, question responses, and reporter identity where Record name is enabled.
What evidence should you capture for an ISO 27001 assessor?
An assessor reviewing ISO 27001 control 6.8 usually needs to see both the reporting mechanism and proof that it is available to personnel. Capture evidence after configuration and again during your periodic control review.
- A screenshot of the form title, description, and reporting instructions, including the urgent escalation language.
- Screenshots of the Settings panel showing Only people in my organization can respond, Record name, Accept responses, and response email notifications.
- Screenshots of the required questions and any branching logic, with production report content redacted where necessary.
- A screenshot of the published form link in the employee handbook, onboarding documentation, or Microsoft Teams security channel.
- A redacted test submission from the Responses tab, plus the corresponding notification email received by the triage mailbox.
- An Open in Excel export for a test period, stored in your compliance evidence repository with access restricted to authorized personnel.
- Your incident management procedure showing who reviews submissions, expected triage timing, escalation criteria, and how incidents are tracked to closure.
Where does Microsoft Forms fall short, and what fills the gap?
A Microsoft Forms security reporting workflow is an intake mechanism, not a complete incident-management system. Forms does not assign incident owners, enforce response-time service levels, create investigation timelines, correlate alerts, preserve forensic evidence, or provide an auditable case-management lifecycle. It also should not be the only emergency path for an active account compromise or production outage.
Fill those gaps with a documented incident response procedure and a monitored triage destination. For example, use Power Automate with the Microsoft Forms connector to create a ticket in your approved ticketing platform when a response is submitted, then assign an owner, set severity, and record containment and closure decisions there. For urgent cases, maintain a separate, clearly published security on-call contact. In Azure-centered environments, use Microsoft Entra ID sign-in logs, Microsoft Defender alerts, Azure Activity Log data, and Azure Monitor or Microsoft Sentinel records as investigation evidence after the report is received.
Also decide deliberately whether confidential reporting is needed. Recording names supports follow-up, but some organizations may need an additional route for sensitive concerns. If you provide an anonymous channel, document how it is monitored and how reporters can receive instructions without exposing their identity. The key control outcome is not merely collecting a form response; it is ensuring personnel can report promptly and that the organization can act on the report.
Next step: create the form, run one documented test submission, and attach the resulting screenshots and triage evidence to your enterprise questionnaire response for ISO 27001 control 6.8.