Adoption means using the five phases in Part 1: plan and prepare; detect and report; assess and decide; respond; and learn lessons. The organization decides the scope, classification criteria, roles, authorities, communications, records, tools, and review cycle that fit its services, risk situation, size, and structure.
Part 2 turns the preparation and learning phases into an operating capability: an approved policy, an incident-management plan, an incident management team (IMT), incident response teams (IRTs) where needed, internal and external relationships, technical support, awareness, training, exercises, monitoring, and improvements. Part 3 supplies the detailed ICT operations inside the middle phases. It does not cover non-ICT response such as a lost paper document.
ISO/IEC 27035 does not impose statutory notification deadlines and is not a standalone certifiable management-system standard. It can support ISO/IEC 27001:2022 Annex A controls 5.24 through 5.28, but ISO/IEC 27001 governs an organization's information security management system and any certification against it. Applicable laws, regulatory instructions, contracts, insurance terms, and continuity plans remain separate requirements.
Parts 1 and 2 are second editions published in February 2023. Part 3 is the first edition, published in September 2020, and ISO currently lists it at the close-of-review stage. These publication dates are not statutory commencement or transition dates. When maintaining controlled procedures, confirm the current ISO edition and any law, contract, certification scope, or customer commitment that incorporates a specific edition.