---
title: "ISO/IEC 27035 Compliance Guide"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27035/compliance"
source_url: "https://www.sorena.io/artifacts/global/iso-27035/compliance"
author: "Sorena AI"
description: "Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme."
published_at: "2026-05-09"
updated_at: "2026-07-16"
keywords:
  - "ISO/IEC 27035 Compliance"
  - "ISO/IEC 27035"
  - "ISO/IEC 27035 Information Security Incident Management"
  - "ISO/IEC 27035 Compliance checklist"
  - "ISO/IEC 27035 Compliance evidence"
  - "ISO/IEC 27035 Compliance implementation"
  - "Guide"
  - "global Compliance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ISO/IEC 27035 Compliance Guide

Understand what the ISO/IEC 27035 series covers, how its three published parts fit together, and how to adopt the guidance without mistaking it for a law or certification scheme.

*Guide* *Global* *ISO/IEC 27035*

## ISO/IEC 27035 Compliance

ISO/IEC 27035 is voluntary guidance, not a law or standalone certification scheme. Adapt it to the incident and apply separate legal, regulatory, contractual, and ISO/IEC 27001 requirements where relevant.

ISO/IEC 27035 is a voluntary incident-management guidance series for organizations of any type or size. Part 1 sets the principles and five-phase process, Part 2 explains how to plan, prepare, test, and learn, and Part 3 details ICT detection, triage, analysis, containment, eradication, recovery, and reporting.

## What does adopting ISO/IEC 27035 actually mean?

Adoption means building a structured incident-management capability around five phases: plan and prepare; detect and report; assess and decide; respond; and learn lessons. The organization adapts that process to its size, risk, services, and operating model.

ISO/IEC 27035 does not impose statutory reporting deadlines and is not a standalone certifiable management-system standard. It provides deeper process guidance that can support ISO/IEC 27001:2022 Annex A controls 5.24 through 5.28 and the corresponding ISO/IEC 27002 implementation guidance; the organization's ISMS, Statement of Applicability, and conformity assessment remain governed by ISO/IEC 27001. Legal, regulatory, and contractual duties remain separate overlays.

- Identify which parts of the series are in scope: Part 1 for principles and process, Part 2 for readiness and improvement, and Part 3 for ICT response operations.
- Name an incident coordinator, incident management team (IMT), incident response team (IRT), points of contact, and decision authorities appropriate to the organization.
- Keep the policy, plan, classification scale, event reports, incident log, response records, tests, and lessons-learned actions as evidence that the capability operates.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - Primary ISO listing for incident management principles and process.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - Primary ISO listing for planning, preparing, and lessons-learned guidance.
- [ISO/IEC 27001:2022 standard page](https://www.iso.org/standard/82875.html?ref=sorena.io) - ISMS requirements source whose Annex A controls 5.24 through 5.28 cover incident planning, event assessment, response, learning, and evidence collection.
- [ISO/IEC 27002:2022 standard page](https://www.iso.org/standard/75652.html?ref=sorena.io) - Implementation guidance for the information security controls referenced by ISO/IEC 27001 Annex A.

## Which records should prove ISO/IEC 27035 Compliance is implemented correctly?

Evidence should be collected where the work actually happens. For ISO/IEC 27035, that usually means incident policy, incident response plan, IMT/IRT roles, severity matrix, event triage records, escalation logs, notification evidence, containment and recovery records, lessons learned, and retained logs.

A strong evidence set tells a visitor, auditor, customer, or decision owner what was decided, why it was reasonable, who approved it, and when it must be reviewed again.

- Artifact-specific evidence: incident policy, response plan, severity matrix, triage records, escalation logs, notifications, containment and recovery notes, lessons learned, and retained logs.
- Decision record: scope, assumption, risk or obligation, owner, approval, and date.
- Operation record: ticket, log, review, test, contract clause, register entry, or control sample showing the process ran.
- Review record: result, exception, corrective action, next owner, and next review date.

Sources for this answer:

- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - Primary ISO listing for planning, preparing, and lessons-learned guidance.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - Primary ISO listing for ICT incident response operations guidance.

## How should teams turn ISO/IEC 27035 Compliance into a repeatable workflow?

Build the workflow around a small number of durable checkpoints: intake, classification, owner assignment, evidence request, decision, review, and escalation. This keeps the work usable across audits, customer assurance, and operational reviews.

Avoid overfitting the workflow to one audit cycle. The same record should help during normal operations, change review, incident response, supplier review, or management review depending on the topic.

- Intake: describe the system, service, supplier, control, event, incident, or process affected.
- Classification: distinguish event validation, incident severity, response authority, evidence handling, notification review, continuity, and supplier coordination.
- Escalation: route exceptions to the person or forum that can accept risk or fund remediation.

Sources for this answer:

- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - Primary ISO listing for ICT incident response operations guidance.
- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - Primary ISO listing for incident management principles and process.

*Recommended next step*

*Placement: after implementation guidance*

## Operationalize ISO/IEC 27035 Compliance

This page moves ISO/IEC 27035 guidance into an auditable operating loop with owners, evidence requests, decision records, and scheduled review dates.

- [Open Assessment Autopilot for ISO/IEC 27035](/solutions/assessment.md): Convert ISO/IEC 27035 Compliance into accountable tasks, evidence requests, and review checkpoints.
- [Talk through ISO/IEC 27035 implementation](/contact.md): Review your current scope, evidence gaps, and next implementation steps.

## What mistakes make ISO/IEC 27035 Compliance weak or hard to audit?

The common failure is writing generic Compliance copy that cannot be connected to a real owner, system, supplier, recovery target, control sample, or risk decision. That makes the page look complete but leaves no proof when someone asks how it works.

Another failure is mixing standards and regulations without stating which source creates the requirement. Use ISO standards to structure management-system practice, and use legal sources separately when a binding obligation applies.

- Do not cite a standard title as evidence that a process is operating.
- Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
- Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.

Sources for this answer:

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - Primary ISO listing for incident management principles and process.
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - Primary ISO listing for planning, preparing, and lessons-learned guidance.

## How should teams review and improve ISO/IEC 27035 Compliance over time?

Review should happen during each incident, after exercises, after major control or threat changes, and during lessons-learned and management-review cycles. If the review changes the decision, update the register, workflow, control evidence, or contract record that downstream teams rely on.

Improvement is strongest when the same evidence supports multiple needs: internal audits, customer assurance, regulatory mapping, supplier governance, incident reviews, and management review.

- Set a review date and a change-trigger rule.
- Track findings until closure and connect them to corrective actions or risk acceptance.
- Use management review to decide resourcing, risk appetite, scope changes, and evidence quality.

Sources for this answer:

- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - Primary ISO listing for planning, preparing, and lessons-learned guidance.
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - Primary ISO listing for ICT incident response operations guidance.

## Primary sources

- [ISO/IEC 27035-1:2023 standard page](https://www.iso.org/standard/78973.html?ref=sorena.io) - Primary ISO listing for incident management principles and process.
  - Quote: "preparing for, detecting, reporting, assessing, and responding to incidents"
- [ISO/IEC 27035-2:2023 standard page](https://www.iso.org/standard/78974.html?ref=sorena.io) - Primary ISO listing for planning, preparing, and lessons-learned guidance.
  - Quote: "plan and prepare for incident response and to learn lessons"
- [ISO/IEC 27035-3:2020 standard page](https://www.iso.org/standard/74033.html?ref=sorena.io) - Primary ISO listing for ICT incident response operations guidance.
  - Quote: "information security incident response in ICT security operations"

## Related Topic Guides

- [ISO/IEC 27035 CSIRT Roles FAQ](/artifacts/global/iso-27035/faq/csirt-roles.md): Assign ISO/IEC 27035 incident coordinator, IMT, IRT or CSIRT, point-of-contact, evidence, communications, and business decision roles.
- [ISO/IEC 27035 Escalation FAQ](/artifacts/global/iso-27035/faq/escalation.md): Define ISO/IEC 27035 escalation and elevation triggers, authorities, handoff evidence, and reassessment rules before incidents occur.
- [ISO/IEC 27035 Event vs Incident FAQ](/artifacts/global/iso-27035/faq/event-vs-incident.md): Distinguish an information security event from an incident under ISO/IEC 27035 and record the assessment without discarding useful event evidence.
- [ISO/IEC 27035 Evidence Log Template and Workflow](/artifacts/global/iso-27035/evidence-log-template.md): Use an ISO/IEC 27035-aligned incident log to preserve facts, decisions, actions, communications, evidence references, and chain-of-custody information.
- [ISO/IEC 27035 Incident Lifecycle Guide](/artifacts/global/iso-27035/incident-lifecycle.md): Follow the ISO/IEC 27035 five-phase incident-management process and understand how the detailed ICT response loop fits inside it.
- [ISO/IEC 27035 Incident Lifecycle Workflow](/artifacts/global/iso-27035/incident-lifecycle-workflow.md): Turn the ISO/IEC 27035 lifecycle into an operational workflow with explicit decisions, handoffs, owners, evidence, and reopening triggers.
- [ISO/IEC 27035 Incident Management FAQ](/artifacts/global/iso-27035/faq.md): Plain-language ISO/IEC 27035 answers on events, incidents, roles, severity, escalation, evidence, notification, retention, review, and lessons learned.
- [ISO/IEC 27035 Incident Response Playbook](/artifacts/global/iso-27035/incident-response-playbook.md): Build ISO/IEC 27035-aligned playbooks that guide detection, triage, analysis, containment, eradication, recovery, reporting, and evidence preservation.
- [ISO/IEC 27035 Incident Severity and Escalation Matrix](/artifacts/global/iso-27035/incident-severity-and-escalation-matrix.md): Design an ISO/IEC 27035-aligned severity and escalation matrix using impact, priority, damage, urgency, recoverability, and reporting triggers.
- [ISO/IEC 27035 Incident Timer Workflow Template and Workflow](/artifacts/global/iso-27035/incident-timer-workflow.md): Create an incident clock that tracks operational checkpoints and separate legal or contractual deadlines without inventing ISO/IEC 27035 time limits.
- [ISO/IEC 27035 Lessons Learned FAQ](/artifacts/global/iso-27035/faq/lessons-learned.md): Apply ISO/IEC 27035 lessons learned to plans, controls, risk decisions, training, relationships, metrics, and future response capability.
- [ISO/IEC 27035 Notification Evidence FAQ](/artifacts/global/iso-27035/faq/notification-evidence.md): Preserve evidence for internal and external incident notifications without attributing legal deadlines or reporting duties to ISO/IEC 27035.
- [ISO/IEC 27035 Notification Threshold Mapping Guide](/artifacts/global/iso-27035/notification-threshold-mapping.md): Map ISO/IEC 27035 incident reporting routes to separate legal, contractual, customer, supplier, insurer, and internal notification thresholds.
- [ISO/IEC 27035 Post Incident Review FAQ](/artifacts/global/iso-27035/faq/post-incident-review.md): Run an ISO/IEC 27035 post-incident review after stabilization and recovery, then assign measurable improvements without losing accountability.
- [ISO/IEC 27035 Retained Logs FAQ](/artifacts/global/iso-27035/faq/retained-logs.md): Retain ISO/IEC 27035 incident logs and digital evidence according to purpose, investigation needs, law, contracts, privacy, and organizational policy.
- [ISO/IEC 27035 Severity Classification FAQ](/artifacts/global/iso-27035/faq/severity-classification.md): Classify incident severity under ISO/IEC 27035 using organization-specific criteria and reassess it as facts, impact, and recoverability change.
- [ISO/IEC 27035 vs ISO 22301 Comparison](/artifacts/global/iso-27035/iso-27035-vs-iso-22301.md): Compare ISO/IEC 27035 incident-management guidance with ISO 22301 business continuity management-system requirements and certification scope.
- [ISO/IEC 27035 vs NIS2 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nis2.md): Compare voluntary ISO/IEC 27035 incident-management guidance with binding NIS2 duties for in-scope EU entities and national implementation.
- [ISO/IEC 27035 vs NIST SP 800-61 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nist-800-61.md): Compare ISO/IEC 27035 with the current NIST SP 800-61 Rev. 3 while preserving this legacy route for visitors using the older publication name.
- [ISO/IEC 27035 vs NIST SP 800-61 Rev. 3 Comparison](/artifacts/global/iso-27035/iso-27035-vs-nist-800-61r3.md): Compare the ISO/IEC 27035 series with NIST SP 800-61 Rev. 3 incident-response guidance and show how organizations can use both.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27035/compliance.md
