GuideGlobalISO/IEC 27035

ISO/IEC 27035 Compliance

Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Adapt it to the incident and apply separate legal, regulatory, contractual, and ISO/IEC 27001 requirements where relevant.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Adopting ISO/IEC 27035 means tailoring a documented incident-management capability to the organization's risks and operations, including criteria for deciding when an information security event is an . Part 1:2023 provides the principles and five-phase process, Part 2:2023 covers planning, preparation, testing, and lessons learned, and Part 3:2020 covers ICT response operations. The series is guidance for organizations of any type or size; it does not create a certification or replace applicable law.

Section 1

What does adopting ISO/IEC 27035 mean?

Adoption means using the five phases in Part 1: plan and prepare; detect and report; assess and decide; respond; and learn lessons. The organization decides the scope, classification criteria, roles, authorities, communications, records, tools, and review cycle that fit its services, risk situation, size, and structure.

Part 2 turns the preparation and learning phases into an operating capability: an approved policy, an incident-management plan, an incident management team (IMT), incident response teams (IRTs) where needed, internal and external relationships, technical support, awareness, training, exercises, monitoring, and improvements. Part 3 supplies the detailed ICT operations inside the middle phases. It does not cover non-ICT response such as a lost paper document.

ISO/IEC 27035 does not impose statutory notification deadlines and is not a standalone certifiable management-system standard. It can support ISO/IEC 27001:2022 Annex A controls 5.24 through 5.28, but ISO/IEC 27001 governs an organization's information security management system and any certification against it. Applicable laws, regulatory instructions, contracts, insurance terms, and continuity plans remain separate requirements.

Parts 1 and 2 are second editions published in February 2023. Part 3 is the first edition, published in September 2020, and ISO currently lists it at the close-of-review stage. These publication dates are not statutory commencement or transition dates. When maintaining controlled procedures, confirm the current ISO edition and any law, contract, certification scope, or customer commitment that incorporates a specific edition.

  • Use Part 1 across the incident-management capability, Part 2 for readiness and improvement, and Part 3 when the response concerns ICT systems, networks, services, or data.
  • Assign an incident coordinator, an IMT, one or more IRTs where appropriate, points of contact, and named authorities for classification, escalation, containment, recovery, external reporting, and closure.
  • Document how legal, regulatory, contractual, supplier, customer, insurer, law-enforcement, and continuity requirements enter the process without attributing those duties to ISO/IEC 27035.
  • Include permanent staff, contractors, ICT and telecommunications providers, outsourcing companies, and external response services where their systems, data, logs, approvals, or actions are needed to report or resolve an incident.
Section 2

What records show that the capability is operating?

A policy or standard purchase does not show that the capability works. Keep the records created during preparation, exercises, events, incidents, and improvement work. Part 1 calls for event reports, an incident-management log, and a centrally managed incident register; Part 2 adds the policy, plan, team arrangements, training, exercises, capability monitoring, and lessons-learned actions.

Each incident record should let an authorized reviewer reconstruct what was reported, what the organization knew at each decision point, whether the event was classified as an incident, who acted, how severity changed, what was communicated, which evidence was preserved, how recovery and closure were approved, and which follow-up actions remain open. Apply access, retention, confidentiality, and evidence-preservation rules appropriate to the record and any external duty.

  • Governance evidence: approved policy, plan, scope, classification scale, role and authority matrix, contact lists, communication rules, and external-requirement mapping.
  • Readiness evidence: training and awareness records, exercise objectives and results, tool and access checks, supplier or specialist arrangements, and tracked readiness gaps.
  • Operational evidence: event report, classification decision, incident log, severity changes, response actions, notifications, evidence custody, recovery validation, closure decision, and incident-register entry.
  • Improvement evidence: lessons learned, IRT evaluation, control and risk-assessment changes, corrective-action owners, due dates, and verification of closure.
Section 3

How should an organization implement the series?

Start with the organization's risk and operating context, not a generic maturity score. Define the capability, approve the policy and plan, establish teams and relationships, prepare the reporting and recordkeeping mechanisms, train the people in scope, and test the plan. Use exercise and incident findings to change the plan, controls, risk assessment, and team capability.

During an event, the point of contact records enough information for the incident coordinator to assess it against the approved criteria. If it is an incident, the assigned team manages the response, updates the incident log and register, reassesses classification as facts change, coordinates required communications, preserves relevant evidence, validates recovery, and records closure and follow-up.

  • Define: scope, objectives, policy owner, review cycle, event and incident criteria, severity scale, reporting routes, authorities, records, and external dependencies.
  • Prepare: establish the IMT and IRT arrangements, contacts, tools, secure communications, specialist support, training, exercises, and continuity handoffs.
  • Operate: record the event, assess and decide, respond, communicate, preserve evidence, recover, conclude, and keep the incident register current.
  • Improve: evaluate the response and teams, assign corrective actions, update affected controls and risk assessments, and test the changed capability.
Section 4

What does ISO/IEC 27035 adoption not establish?

Adoption does not by itself establish conformity with ISO/IEC 27001, compliance with a law, satisfaction of a contract, or that every incident was handled correctly. Those conclusions depend on the applicable criteria and evidence. ISO/IEC 27035 supplies guidance for the organization to tailor and operate.

Keep an information security event, an , an internal escalation, and an externally reportable incident as separate decisions. An event may be assessed and closed without becoming an incident; an incident may require internal response without meeting an external reporting threshold; and a legal clock may start under rules that use different definitions.

  • Do not call the series a certification standard or describe an organization as 'ISO/IEC 27035 certified' without a separate, valid basis for that claim.
  • Do not copy the sample alarm levels or examples in the standards without mapping them to the organization's assets, services, risk criteria, and decision authority.
  • Do not let a severity rating override a separate legal, contractual, safety, privacy, insurer, or continuity trigger.
  • Do not close an incident because systems are available again if reporting, evidence preservation, cause analysis, register updates, or improvement actions still need ownership.
Section 5

When should the capability be reviewed?

Set a planned review cycle for the policy, plan, contacts, classification criteria, response procedures, tools, training, and external-requirement mapping. Review sooner after an incident or exercise exposes a gap, or when services, technology, suppliers, threats, organizational structure, laws, contracts, or continuity arrangements materially change.

Part 2's lessons-learned phase covers identifying improvement areas, changing the incident-management plan and control implementation, feeding results into risk assessment and management review, and evaluating the IRT. Track each action to an owner and verify that the revised process works; recording a lesson without changing or testing anything does not show improvement.

  • Reassess live incidents whenever scope, impact, threat activity, recoverability, evidence, or an external reporting trigger changes.
  • After an incident or exercise, compare the actual decisions and handoffs with the plan and record where the plan, training, authority, tools, or relationships failed.
  • Retest material changes and retain the result, unresolved exception, accountable owner, and next review date.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO identifies ISO/IEC 27001:2022 as the requirements standard for an information security management system; its Annex A contains the incident-management control set that ISO/IEC 27035 can support.
iso.org
Referenced sections
  • ISO identifies ISO/IEC 27002:2022 as guidance for information security controls, including the controls referenced by ISO/IEC 27001 Annex A.
iso.org
Referenced sections
  • Part 1 treats event assessment, incident classification, response, documentation, and lessons learned as distinct parts of the process.
iso.org
Referenced sections
  • Part 2 expressly covers identifying improvement areas, improving the plan and controls, feeding results into risk and management review, and evaluating the IRT.
iso.org
Referenced sections
  • Part 3 provides the operational ICT activities whose outcomes should be compared with the plan during incident review.
Related guides

Explore more topics

ISO/IEC 27035 CSIRT Roles FAQ
Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
ISO/IEC 27035 Escalation FAQ
Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
ISO/IEC 27035 Event vs Incident FAQ
Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
ISO/IEC 27035 Evidence Log Template
Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
ISO/IEC 27035 Incident Lifecycle Guide
Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
ISO/IEC 27035 Incident Lifecycle Workflow
Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
ISO/IEC 27035 Incident Management FAQ
Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
ISO/IEC 27035 Incident Response Playbook
Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
ISO/IEC 27035 Incident Severity and Escalation Matrix
Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
ISO/IEC 27035 Incident Timer Workflow
Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
ISO/IEC 27035 Lessons Learned FAQ
Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
ISO/IEC 27035 Notification Evidence FAQ
Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
ISO/IEC 27035 Notification Threshold Mapping Guide
Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
ISO/IEC 27035 Post Incident Review FAQ
Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
ISO/IEC 27035 Retained Logs FAQ
Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
ISO/IEC 27035 Severity Classification FAQ
Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
ISO/IEC 27035 vs ISO 22301 Comparison
Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
ISO/IEC 27035 vs NIS2 Comparison
Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
ISO/IEC 27035 vs NIST SP 800-61 Comparison
Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison
Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.