---
title: "ISO/IEC 27035 Information Security Incident Management Guide"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27035"
source_url: "https://www.sorena.io/artifacts/global/iso-27035"
author: "Sorena AI"
description: "Plain-language ISO/IEC 27035 guide to incident preparation, detection, assessment, response, evidence, escalation, recovery, and lessons learned."
published_at: "2026-03-04"
updated_at: "2026-07-16"
keywords:
  - "ISO/IEC 27035"
  - "information security incident management"
  - "incident response evidence"
  - "incident management checklist"
  - "ISO/IEC 27035 Information Security Incident Management"
  - "global standards"
  - "compliance evidence"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ISO/IEC 27035 Information Security Incident Management Guide

Plain-language ISO/IEC 27035 guide to incident preparation, detection, assessment, response, evidence, escalation, recovery, and lessons learned.

![ISO/IEC 27035 artifact preview](https://cdn.sorena.io/cdn-cgi/image/width=1200,quality=88,format=auto/images/3rd-parties/iso.jpg)

*ISO/IEC 27035* *Free Resource*

## ISO/IEC 27035 Incident-management guidance, workflows, evidence, and comparisons

Use the ISO/IEC 27035 standards series to prepare for, detect, report, assess, respond to, and learn from information security incidents.

The current published series combines Part 1, Edition 2 (February 2023), for principles and the five-phase process; Part 2, Edition 2 (February 2023), for planning, preparation, testing, and lessons learned; and Part 3, Edition 1 (September 2020), for ICT response operations. Part 3 is limited to ICT incidents and remains the published edition after ISO closed its systematic review on 3 December 2025; the broader Part 1 process can also cover non-ICT events such as lost paper records. ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Legal reporting duties, contracts, and continuity plans must be assessed separately.

[Jump to guides](#topics)

## What this hub helps you do

- **Incident lifecycle**: Prepare, detect, report, assess, respond, recover, and learn with ownership and evidence at each handoff.
- **Severity and timers**: Set organization-specific severity criteria, escalation authority, reassessment triggers, and separate legal or contractual notification clocks.
- **Evidence log**: Preserve the event report, classification decision, incident chronology, response actions, notifications, evidence handling, closure, and follow-up.

By Sorena AI | Updated 2026 | No signup required

### Quick scan

*ISO/IEC 27035*

- **Incident lifecycle**: Prepare, detect, report, assess, respond, recover, and learn with ownership and evidence at each handoff.
- **Severity and timers**: Set organization-specific severity criteria, escalation authority, reassessment triggers, and separate legal or contractual notification clocks.
- **Evidence log**: Preserve the event report, classification decision, incident chronology, response actions, notifications, evidence handling, closure, and follow-up.

Start with an event report. Record the incident coordinator's decision, then give every classification, action, escalation, communication, recovery, and closure decision an owner, timestamp, rationale, supporting evidence, and reassessment trigger.

| Value | Metric |
| --- | --- |
| Guides | Deep pages |
| FAQ | Standalone answers |
| Compare | Side-by-side |
| Evidence | Reusable |

**Key highlights:** Scope | Evidence | Review

## Definitions

### Information security incidents

Information security incidents are related and identified information security events that can harm an organization's assets or compromise its operations. An event report becomes an incident record only after the organization's criteria and authorized assessment support that classification.

**Why it matters here:** ISO/IEC 27035 separates detection and reporting from assessment and response. The organization should record who classified the event, the evidence and criteria used, the severity, the response owner, and each later reassessment.

Sources:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io)

### ICT incidents

ICT incidents are information security incidents involving information and communication technology systems or operations. Part 3 covers technical response activities such as detection, reporting, triage, analysis, containment, eradication, recovery, and conclusion.

**Why it matters here:** Part 3's ICT focus is narrower than the Part 1 management process. An organization can use the broader process for incidents involving non-ICT information, people, physical records, or services while applying Part 3 to the technical response where relevant.

Sources:

- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io)

## Primary sources

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - ISO's current published listing identifies Edition 2, published in February 2023, as the foundation of the series and describes its generic five-phase incident-management process.
  - Quote: "preparing for, detecting, reporting, assessing, and responding to incidents"
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - ISO's current published listing identifies Edition 2, published in February 2023, and covers policy, the incident-management plan, teams, relationships, support, training, testing, and lessons learned.
  - Quote: "plan and prepare for incident response and to learn lessons"
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - ISO's listing identifies the 2020 first edition for ICT detection, reporting, triage, analysis, containment, eradication, recovery, and conclusion. It records the close of systematic review on 3 December 2025 and continues to list this edition as published.
  - Quote: "information security incident response in ICT security operations"
- [ISO/IEC 27001:2022 standard page](https://www.iso.org/standard/82875.html?ref=sorena.io) - ISMS requirements source that includes the Annex A incident-management controls supported by ISO/IEC 27035 process guidance.
  - Quote: "Information security management systems - Requirements"
- [ISO/IEC 27002:2022 standard page](https://www.iso.org/standard/75652.html?ref=sorena.io) - Implementation guidance for information security controls, including the incident-management control set.
  - Quote: "Information security controls"

*Recommended reading path*

## Choose the next incident-management decision

Start with the series and lifecycle, then move to preparation, live response, evidence and escalation, external obligations, or a focused comparison. These pages explain the published standards but do not replace them or determine duties under applicable law.

### 1. Start here: understand the series and lifecycle

Understand what Parts 1, 2, and 3 cover, how an organization decides whether an event is an incident, and how the five management phases connect to ICT response operations.

1. [ISO/IEC 27035 Compliance Guide](/artifacts/global/iso-27035/compliance.md): Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.
2. [ISO/IEC 27035 Incident Lifecycle Guide](/artifacts/global/iso-27035/incident-lifecycle.md): Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
3. [ISO/IEC 27035 Incident Management FAQ](/artifacts/global/iso-27035/faq.md): Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.

### 2. Prepare and operate the response

Turn the lifecycle into an owned plan, tested playbooks, clear handoffs, and an operational workflow for detection through recovery.

4. [ISO/IEC 27035 Incident Response Playbook](/artifacts/global/iso-27035/incident-response-playbook.md): Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
5. [ISO/IEC 27035 Incident Lifecycle Workflow](/artifacts/global/iso-27035/incident-lifecycle-workflow.md): Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
6. [ISO/IEC 27035 Incident Timer Workflow](/artifacts/global/iso-27035/incident-timer-workflow.md): Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.

### 3. Classify, escalate, and preserve evidence

Define severity criteria, escalation authority, decision records, and evidence handling before an incident requires time-sensitive decisions.

7. [ISO/IEC 27035 Incident Severity and Escalation Matrix](/artifacts/global/iso-27035/incident-severity-and-escalation-matrix.md): Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
8. [ISO/IEC 27035 Evidence Log Template](/artifacts/global/iso-27035/evidence-log-template.md): Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
9. [ISO/IEC 27035 Notification Threshold Mapping Guide](/artifacts/global/iso-27035/notification-threshold-mapping.md): Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.

### 4. Connect ISO/IEC 27035 to other requirements

Keep voluntary incident-management guidance distinct from laws, certifiable management-system standards, continuity requirements, and other response frameworks.

10. [ISO/IEC 27035 vs NIS2 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nis2.md): Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
11. [ISO/IEC 27035 vs ISO 22301 Comparison](/artifacts/global/iso-27035/iso-27035-vs-iso-22301.md): Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
12. [ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nist-800-61r3.md): Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.
13. [ISO/IEC 27035 vs NIST SP 800-61 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nist-800-61.md): Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.

### 5. More guides

Additional guidance related to this artifact.

14. [ISO/IEC 27035 CSIRT Roles FAQ](/artifacts/global/iso-27035/faq/csirt-roles.md): Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
15. [ISO/IEC 27035 Escalation FAQ](/artifacts/global/iso-27035/faq/escalation.md): Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
16. [ISO/IEC 27035 Event vs Incident FAQ](/artifacts/global/iso-27035/faq/event-vs-incident.md): Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
17. [ISO/IEC 27035 Lessons Learned FAQ](/artifacts/global/iso-27035/faq/lessons-learned.md): Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
18. [ISO/IEC 27035 Notification Evidence FAQ](/artifacts/global/iso-27035/faq/notification-evidence.md): Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
19. [ISO/IEC 27035 Post Incident Review FAQ](/artifacts/global/iso-27035/faq/post-incident-review.md): Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
20. [ISO/IEC 27035 Retained Logs FAQ](/artifacts/global/iso-27035/faq/retained-logs.md): Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
21. [ISO/IEC 27035 Severity Classification FAQ](/artifacts/global/iso-27035/faq/severity-classification.md): Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.

## Explore ISO/IEC 27035 guides

*Guides*

Use these pages to move from ISO/IEC 27035 overview to practical evidence, FAQ answers, comparisons, and workflows.

*Next step*

## Build a cited ISO/IEC 27035 workflow

Assign owners to the policy, plan, response roles, incident records, exercises, and improvement actions, then connect each item to the applicable standard or external duty.

- Start from the ISO/IEC 27035 page that matches the decision or evidence gap.
- Open Research Copilot for interpretation questions tied to cited sources.
- Use a single source of truth to keep evidence, owners, and review history governed in one place.

- [Open Research Copilot](/solutions/research-copilot.md): Answer ISO/IEC 27035 scope and interpretation questions with cited outputs.
- [Open SSOT](/solutions/ssot.md): Keep ISO/IEC 27035 evidence, decisions, and control records in one governed system.
- [Talk through implementation](/contact.md): Review scope, evidence gaps, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27035.md
